CVE-2025-0679: Exposure of Private Personal Information to an Unauthorized Actor in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions from 17.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Under certain conditions un-authorised users can view full email addresses that should be partially obscured.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-0679?
CVE-2025-0679 has a medium severity rating due to its potential impact on user privacy.
How do I fix CVE-2025-0679?
To fix CVE-2025-0679, upgrade GitLab CE/EE to version 17.10.7, 17.11.3, or 18.0.1 or later.
What versions of GitLab are affected by CVE-2025-0679?
CVE-2025-0679 affects GitLab CE/EE versions from 17.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1.
What specific issue does CVE-2025-0679 cause?
CVE-2025-0679 allows unauthorized users to view full email addresses that should be partially obscured.
Is there a workaround for CVE-2025-0679?
No official workaround is recommended for CVE-2025-0679; upgrading to a fixed version is advised.