CVE-2025-1198: Insufficient Session Expiration in GitLab
An issue discovered in GitLab CE/EE affecting all versions from 16.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 meant that long-lived connections in ActionCable potentially allowed revoked Personal Access Tokens access to streaming results.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-1198?
The severity of CVE-2025-1198 is considered to be high due to the potential unauthorized access it allows.
How do I fix CVE-2025-1198?
To fix CVE-2025-1198, upgrade your GitLab CE/EE installation to version 17.6.5, 17.7.4, or 17.8.2 or later.
Which versions of GitLab are affected by CVE-2025-1198?
CVE-2025-1198 affects all GitLab CE/EE versions from 16.11 up to but not including 17.6.5, 17.7 up to 17.7.4, and 17.8 up to 17.8.2.
What type of attack is possible due to CVE-2025-1198?
CVE-2025-1198 allows revoked Personal Access Tokens to potentially access streaming results, posing a risk of unauthorized data exposure.
Is CVE-2025-1198 a remote vulnerability?
Yes, CVE-2025-1198 is a remote vulnerability that can be exploited through long-lived connections in ActionCable.