External User Permissions Issue in GitLab CE/EE Products
CVE-2025-1540

4.2MEDIUM

Key Information:

Vendor

Gitlab

Status
Vendor
CVE Published:
6 March 2025

What is CVE-2025-1540?

A permission manipulation issue has been identified in GitLab CE/EE that affects self-managed and dedicated instances. This vulnerability allows users designated as External to improperly access and replicate internal projects in specific scenarios. The flaw spans multiple versions, including all releases from 17.5 up to 17.6.5, 17.7 up to 17.7.4, and 17.8 up to 17.8.2, posing a risk to sensitive project data. Immediate attention is warranted to mitigate potential information exposure.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

GitLab 17.5 < 17.6.5

GitLab 17.7 < 17.7.4

GitLab 17.8 < 17.8.2

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thanks [Renato Alves](https://gitlab.com/unode) for reporting this vulnerability.
.