First published: Wed Feb 12 2025(Updated: )
Improper Authorization in GitLab CE/EE affecting all versions from 17.7 prior to 17.7.4, 17.8 prior to 17.8.2 allow users with limited permissions to perform unauthorized actions on critical project data.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab Community Edition | >17.7.4<17.8.2 |
Upgrade to versions 17.7.4, 17.8.2 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0516 is classified as a critical vulnerability due to improper authorization allowing unauthorized actions on critical project data.
To address CVE-2025-0516, it is recommended to upgrade GitLab CE/EE to version 17.7.4 or 17.8.2 or later.
CVE-2025-0516 affects GitLab CE/EE versions from 17.7 prior to 17.7.4 and 17.8 prior to 17.8.2.
Due to CVE-2025-0516, users with limited permissions can perform unauthorized actions that can compromise critical project data.
There are no known workarounds for CVE-2025-0516; the best course of action is to apply the recommended updates.