First published: Thu Feb 13 2025(Updated: )
An issue discovered in GitLab CE/EE affecting all versions from 16.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 meant that long-lived connections in ActionCable potentially allowed revoked Personal Access Tokens access to streaming results.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab Community Edition | >16.11<17.6.5>17.7<17.7.4>17.8<17.8.2 |
Upgrade to versions 17.6.5, 17.7.4, 17.8.2 or above.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-1198 is considered to be high due to the potential unauthorized access it allows.
To fix CVE-2025-1198, upgrade your GitLab CE/EE installation to version 17.6.5, 17.7.4, or 17.8.2 or later.
CVE-2025-1198 affects all GitLab CE/EE versions from 16.11 up to but not including 17.6.5, 17.7 up to 17.7.4, and 17.8 up to 17.8.2.
CVE-2025-1198 allows revoked Personal Access Tokens to potentially access streaming results, posing a risk of unauthorized data exposure.
Yes, CVE-2025-1198 is a remote vulnerability that can be exploited through long-lived connections in ActionCable.