First published: Fri May 09 2025(Updated: )
An issue has been discovered in GitLab CE/EE affecting all versions from 12.0 before 17.9.8, 17.10 before 17.10.6, and 17.11 before 17.11.2. Under certain conditions users could bypass IP access restrictions and view sensitive information.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab Community Edition | >=12.0<17.9.8>=17.10<17.10.6>=17.11<17.11.2 |
Upgrade to versions 17.9.8, 17.10.6, 17.11.2 or above.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-1278 is considered to have a high severity due to its potential to allow unauthorized access to sensitive information.
To fix CVE-2025-1278, upgrade GitLab CE/EE to versions 17.9.8, 17.10.6, or 17.11.2 and later.
CVE-2025-1278 affects all GitLab CE/EE versions from 12.0 before 17.9.8, 17.10 before 17.10.6, and 17.11 before 17.11.2.
The impact of CVE-2025-1278 allows users to bypass IP access restrictions, potentially leading to exposure of sensitive information.
There are no known effective workarounds for CVE-2025-1278, so upgrading is the recommended solution.