CVE-2024-10925: Authorization Bypass Through User-Controlled Key in GitLab
Published Feb 26, 2025
·Updated
A vulnerability in GitLab-EE affecting all versions from 16.2 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows a Guest user to read Security policy YAML
Affected Software
5 affected componentsFixes available
GitLab GitLab-EE>=16.2, <17.7.6, >=17.8, <17.8.4, >=17.9, <17.9.1
GitLab GitLab>=16.2<17.7.6
GitLab GitLab>=17.8.0<17.8.4
GitLab GitLab=17.9.0
GitLab GitLab>=16.2<17.7.6, >=17.8<17.8.4, >=17.9<17.9.1
17.7.617.8.417.9.1
Remediation
Information
Upgrade to versions 17.7.6, 17.8.4, 17.9.1 or above.
Event History
Mar 3, 2025
CVE Published
via MITRE·11:02 AM
Data Sourced
via MITRE·11:02 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Apr 22, 2026
Data Sourced
via GitLab·08:55 AM
DescriptionSeverityAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2024-10925?
CVE-2024-10925 is classified as a medium severity vulnerability.
2
Who is affected by CVE-2024-10925?
CVE-2024-10925 affects GitLab-EE versions from 16.2 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1.
3
How do I fix CVE-2024-10925?
To fix CVE-2024-10925, you should upgrade to GitLab-EE version 17.7.6, 17.8.4, or 17.9.1 or later.
4
What type of access does CVE-2024-10925 grant to attackers?
CVE-2024-10925 allows a Guest user to read sensitive Security policy YAML files.
5
What potential impact does CVE-2024-10925 have on my GitLab instance?
CVE-2024-10925 could lead to exposure of sensitive security information to unauthorized users.