CVE-2025-0307: Planner role can read code review analytics in private projects
Improper authorization in GitLab EE affecting all versions from 17.7 prior to 17.7.6, 17.8 prior to 17.8.4, 17.9 prior to 17.9.1 allow users with limited permissions to access potentially sensitive project analytics data. This is a medium severity issue (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N, 4.3). It is now mitigated in the latest release and is assigned CVE-2025-0307.
Other sources
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
— NVD
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-0307?
CVE-2025-0307 is classified as a medium severity vulnerability.
Which versions of GitLab EE are affected by CVE-2025-0307?
CVE-2025-0307 affects all versions of GitLab EE from 17.7 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1.
How do I fix CVE-2025-0307?
To fix CVE-2025-0307, upgrade GitLab EE to version 17.7.6, 17.8.4, or 17.9.1.
What kind of issue is CVE-2025-0307?
CVE-2025-0307 involves improper authorization allowing users with limited permissions to access sensitive project analytics data.
Can I continue using a vulnerable version of GitLab EE with CVE-2025-0307?
Continuing to use a vulnerable version exposed by CVE-2025-0307 may lead to unauthorized access to sensitive data.