CVE-2025-14562: Incorrect Authorization in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to commit changes to a project after being removed as a member, due to improper authorization checks on merge request collaboration settings.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.0.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.1.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.2.1
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14562?
The severity of CVE-2025-14562 is classified as low with a score of 3.1.
How do I fix CVE-2025-14562?
To fix CVE-2025-14562, upgrade GitLab to version 19.0.5 or later, 19.1.3 or later, or 19.2.1 or later.
What vulnerability type is CVE-2025-14562 associated with?
CVE-2025-14562 is associated with incorrect authorization vulnerabilities.
What versions of GitLab are affected by CVE-2025-14562?
CVE-2025-14562 affects all GitLab versions from 10.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1.
Who can exploit CVE-2025-14562?
An authenticated user with developer-role permissions can exploit CVE-2025-14562 under certain conditions.