CVE-2025-11971: Incorrect Authorization in GitLab
GitLab has remediated an issue in GitLab EE affecting all versions from 10.6 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker to trigger unauthorized pipeline executions by manipulating commits.
Other sources
GitLab has remediated an issue that could have allowed an authenticated user to trigger unauthorized pipeline executions by manipulating commits.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-11971?
The severity of CVE-2025-11971 is considered to be moderate due to its potential for unauthorized pipeline executions by authenticated users.
How do I fix CVE-2025-11971?
To fix CVE-2025-11971, upgrade GitLab EE to version 18.3.5, 18.4.3, or 18.5.1.
Who is affected by CVE-2025-11971?
CVE-2025-11971 affects users of GitLab EE versions between 10.6 and 18.3.5, 18.4, and 18.5.
What type of threat does CVE-2025-11971 pose?
CVE-2025-11971 poses a threat that allows authenticated users to manipulate commits and trigger unauthorized actions.
Is there a patch available for CVE-2025-11971?
Yes, a patch for CVE-2025-11971 is available in the latest versions of GitLab EE.