CVE-2025-0516: Incorrect Authorization in GitLab
Improper Authorization in GitLab CE/EE affecting all versions from 17.7 prior to 17.7.4, 17.8 prior to 17.8.2 allow users with limited permissions to perform unauthorized actions on critical project data.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-0516?
CVE-2025-0516 is classified as a critical vulnerability due to improper authorization allowing unauthorized actions on critical project data.
How do I fix CVE-2025-0516?
To address CVE-2025-0516, it is recommended to upgrade GitLab CE/EE to version 17.7.4 or 17.8.2 or later.
Which versions are affected by CVE-2025-0516?
CVE-2025-0516 affects GitLab CE/EE versions from 17.7 prior to 17.7.4 and 17.8 prior to 17.8.2.
What actions can users with limited permissions perform due to CVE-2025-0516?
Due to CVE-2025-0516, users with limited permissions can perform unauthorized actions that can compromise critical project data.
Is there a workaround for CVE-2025-0516?
There are no known workarounds for CVE-2025-0516; the best course of action is to apply the recommended updates.