CVE-2025-2242: Incorrect Authorization in GitLab
An improper access control vulnerability in GitLab CE/EE affecting all versions from 17.4 prior to 17.8.6, 17.9 prior to 17.9.3, and 17.10 prior to 17.10.1 allows a user who was an instance admin before but has since been downgraded to a regular user to continue to maintain elevated privileges to groups and projects.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-2242?
CVE-2025-2242 is classified as a critical vulnerability due to its impact on access control within GitLab CE/EE.
How do I fix CVE-2025-2242?
To fix CVE-2025-2242, upgrade your GitLab CE/EE installation to version 17.8.6, 17.9.3, or 17.10.1 or later.
Who is affected by CVE-2025-2242?
CVE-2025-2242 affects all users of GitLab CE/EE versions from 17.4 up to 17.10.1, who have had their permissions downgraded.
What type of vulnerability is CVE-2025-2242?
CVE-2025-2242 is an improper access control vulnerability that allows users to maintain elevated privileges.
What happens if CVE-2025-2242 is exploited?
If exploited, CVE-2025-2242 allows downgraded instance admins to retain access to sensitive administrative features they should no longer have.