Authentication Bypass Vulnerability in GitLab Provides Unauthorized Access
CVE-2025-11702
8.5HIGH
What is CVE-2025-11702?
An authentication bypass vulnerability in GitLab's Enterprise Edition has been identified, affecting multiple versions. An authenticated attacker with specific permissions could exploit this flaw to hijack project runners from other projects. This situation arises in versions 17.1 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1. GitLab has released patches to address this security issue, urging users to upgrade to the latest versions to maintain their projects' security and ensure proper permission integrity.
Affected Version(s)
GitLab 17.1 < 18.3.5
GitLab 18.4 < 18.4.3
GitLab 18.5 < 18.5.1
References
CVSS V3.1
Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Thanks [iamgk808](https://hackerone.com/iamgk808) for reporting this vulnerability through our HackerOne bug bounty program