CVE-2025-11340: Incorrect Authorization in GitLab
GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 to 18.3.4, 18.4 to 18.4.2 that, under certain conditions, could have allowed authenticated users with read-only API tokens to perform unauthorized write operations on vulnerability records by exploiting incorrectly scoped GraphQL mutations.
Other sources
GitLab has remediated an issue that, under certain conditions, could have allowed authenticated users with read-only API tokens to perform unauthorized write operations on vulnerability records by exploiting incorrectly scoped GraphQL mutations.Impacted Versions: GitLab EE: all versions from 18.3 to 18.3.4, 18.4 to 18.4.2CVSS: 7.7 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N)
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-11340?
CVE-2025-11340 is classified as a moderate severity vulnerability.
What versions of GitLab EE are affected by CVE-2025-11340?
CVE-2025-11340 affects GitLab EE versions 18.3 to 18.3.4 and 18.4 to 18.4.2.
How do I fix CVE-2025-11340?
To remediate CVE-2025-11340, upgrade GitLab EE to version 18.3.5 or 18.4.3 or later.
What kind of attacks can CVE-2025-11340 enable?
CVE-2025-11340 could allow authenticated users with read-only API tokens to perform unauthorized write operations on vulnerability records.
Is there a patch available for CVE-2025-11340?
Yes, patches for CVE-2025-11340 are included in the updates for affected GitLab EE versions.