CVE-2025-2246: Missing Authorization in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could have allowed unauthenticated users to access sensitive manual CI/CD variables by querying the GraphQL API.
Other sources
GitLab has remediated an issue that could have allowed unauthenticated users to access sensitive manual CI/CD variables by querying the GraphQL API.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-2246?
CVE-2025-2246 is rated as a high severity vulnerability due to its potential to expose sensitive information.
How do I fix CVE-2025-2246?
To fix CVE-2025-2246, upgrade GitLab CE/EE to version 18.1.5, 18.2.5, or 18.3.1 or later.
Who is affected by CVE-2025-2246?
All users of GitLab CE/EE versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 are affected by CVE-2025-2246.
What does CVE-2025-2246 exploit?
CVE-2025-2246 exploits a vulnerability in the GraphQL API that allows unauthenticated users to access sensitive manual CI/CD variables.
What type of vulnerability is CVE-2025-2246?
CVE-2025-2246 is a data exposure vulnerability that allows unauthorized access to sensitive data.