Access Control Vulnerability in GitLab EE Affecting Multiple Versions
CVE-2025-2498
3.1LOW
What is CVE-2025-2498?
An improper access control issue in GitLab EE has been identified that affects users across various versions. This vulnerability may allow unauthorized users to access assigned issues from restricted groups by bypassing established IP restrictions under specific conditions. The impacted versions include those from 12.0 up to 18.0.6, as well as 18.1 up to 18.1.4, and 18.2 up to 18.2.2. Organizations using these versions are encouraged to review their security posture and apply appropriate patches to mitigate potential risks.
Affected Version(s)
GitLab 12.0 < 18.0.6
GitLab 18.1 < 18.1.4
GitLab 18.2 < 18.2.2
References
CVSS V3.1
Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Thanks [rogerace](https://hackerone.com/rogerace) for reporting this vulnerability through our HackerOne bug bounty program