Vulnerability Description
Improper authorization in GitLab EE affecting all versions from 17.7 prior to 17.7.6, 17.8 prior to 17.8.4, 17.9 prior to 17.9.1 allow users with limited permissions to access to potentially sensitive project analytics data.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gitlab | Gitlab | >= 17.7.0, < 17.7.6 |
Related Weaknesses (CWE)
References
- https://gitlab.com/gitlab-org/gitlab/-/issues/512050ExploitIssue Tracking
- https://hackerone.com/reports/2921111Permissions Required
FAQ
What is CVE-2025-2045?
CVE-2025-2045 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Improper authorization in GitLab EE affecting all versions from 17.7 prior to 17.7.6, 17.8 prior to 17.8.4, 17.9 prior to 17.9.1 allow users with limited permissions to access to potentially sensitiv...
How severe is CVE-2025-2045?
CVE-2025-2045 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-2045?
Check the references section above for vendor advisories and patch information. Affected products include: Gitlab Gitlab.