CVE-2025-1110: Insufficient Granularity of Access Control in GitLab
Published May 21, 2025
·Updated
An issue has been discovered in GitLab CE/EE affecting all versions from 18.0 before 18.0.1. In certain circumstances, a user with limited permissions could access Job Data via a crafted GraphQL query.
Affected Software
4 affected componentsFixes available
GitLab GitLab CE/EE>18.0, <18.0.1
GitLab GitLab=18.0.0
GitLab GitLab=18.0.0
GitLab GitLab>=18.0<18.0.1
18.0.1
Remediation
Information
Upgrade to versions 18.0.1 or above.
Event History
May 22, 2025
CVE Published
via MITRE·02:02 PM
Data Sourced
via MITRE·02:02 PM
RemedyDescriptionSeverityWeakness
Apr 22, 2026
Data Sourced
via GitLab·08:55 AM
DescriptionSeverityAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2025-1110?
CVE-2025-1110 has been classified as a high-severity vulnerability.
2
How do I fix CVE-2025-1110?
To fix CVE-2025-1110, upgrade GitLab CE/EE to version 18.0.1 or later.
3
What cause CVE-2025-1110?
CVE-2025-1110 is caused by insufficient access control allowing limited users to access sensitive Job Data through a crafted GraphQL query.
4
Which versions of GitLab are affected by CVE-2025-1110?
CVE-2025-1110 affects all versions of GitLab CE/EE from 18.0 before 18.0.1.
5
What type of attack is CVE-2025-1110 associated with?
CVE-2025-1110 is associated with unauthorized data access attacks via GraphQL queries.