CVE-2025-12704: Missing Authorization in GitLab
GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to access Virtual Registry data in groups where they are not members due to improper authorization under certain conditions.
Other sources
GitLab has remediated an issue that could have allowed an authenticated user to access Virtual Registry data in groups where they are not members due to improper authorization under certain conditions.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-12704?
CVE-2025-12704 is considered a medium severity vulnerability due to improper authorization allowing unauthorized access to Virtual Registry data.
How do I fix CVE-2025-12704?
To fix CVE-2025-12704, upgrade GitLab EE to versions 18.7.6, 18.8.6, or 18.9.2 or later.
Who is affected by CVE-2025-12704?
CVE-2025-12704 affects all authenticated users of GitLab EE who are using versions from 18.2 but earlier than 18.7.6, 18.8 but earlier than 18.8.6, and 18.9 but earlier than 18.9.2.
What could happen if CVE-2025-12704 is exploited?
Exploitation of CVE-2025-12704 could allow an authenticated user to access sensitive Virtual Registry data from groups they do not belong to.
When was CVE-2025-12704 reported?
CVE-2025-12704 was reported prior to its remediation with the patch releases for GitLab EE.