CVE-2025-1908: Business Logic Errors in GitLab
An issue has been discovered in GitLab EE/CE that could allow an attacker to track users' browsing activities, potentially leading to full account take-over, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.
Other sources
An issue has been discovered in GitLab EE/CE that could allow an attacker to track users’ browsing activities, potentially leading to full account take-over, affecting all versions from 16.6 prior to 17.9.7, 17.10 prior to 17.10.5, and 17.11 prior to 17.11.1. This is a high severity issue (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N, 7.7). It is now mitigated in the latest release and is assigned CVE-2025-1908.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-1908?
CVE-2025-1908 has been classified as a high-severity vulnerability that can lead to account take-over.
How do I fix CVE-2025-1908?
To fix CVE-2025-1908, upgrade GitLab EE/CE to version 17.9.7 or later, 17.10.5 or later, or 17.11.1 or later.
What are the affected versions for CVE-2025-1908?
CVE-2025-1908 affects GitLab EE/CE versions from 16.6 before 17.9.7, from 17.10 before 17.10.5, and from 17.11 before 17.11.1.
Can CVE-2025-1908 lead to user privacy issues?
Yes, CVE-2025-1908 could allow attackers to track users' browsing activities, compromising user privacy.
Is CVE-2025-1908 present in recent GitLab releases?
CVE-2025-1908 is not present in GitLab releases after version 17.9.7, 17.10.5, and 17.11.1.