First published: Wed Jan 08 2025(Updated: )
An issue was discovered in GitLab CE/EE affecting all versions starting from 17.4 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. Under certain conditions, access tokens may have been logged when API requests were made in a specific manner.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab Community Edition | >=17.4<17.5.5>=17.6<17.6.3>=17.7<17.7.1 |
Upgrade to version 17.5.5, 17.6.3 or 17.7.1 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0194 is classified as a high severity vulnerability due to the potential exposure of access tokens.
To fix CVE-2025-0194, upgrade GitLab to versions 17.5.5 or 17.6.3, or 17.7.1 or later.
CVE-2025-0194 affects all versions of GitLab CE/EE starting from 17.4 to 17.5.5, 17.6 to 17.6.3, and 17.7 to 17.7.1.
The risks associated with CVE-2025-0194 include unauthorized access due to exposed access tokens in logs.
CVE-2025-0194 was disclosed in January 2025, with a patch released shortly thereafter.