CVE-2025-2469: Debug Messages Revealing Unnecessary Information in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.9.6, and 17.10 before 17.10.4. The runtime profiling data of a specific service was accessible to unauthenticated users.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-2469?
The severity of CVE-2025-2469 is considered to be moderate due to the exposure of sensitive runtime profiling data.
How do I fix CVE-2025-2469?
To fix CVE-2025-2469, upgrade GitLab CE to version 17.9.6 or higher and GitLab EE to version 17.10.4 or higher.
Who is affected by CVE-2025-2469?
CVE-2025-2469 affects all versions of GitLab CE from 17.9 before 17.9.6 and GitLab EE from 17.10 before 17.10.4.
What type of data was exposed in CVE-2025-2469?
CVE-2025-2469 exposed the runtime profiling data of a specific service to unauthenticated users.
Is CVE-2025-2469 exploitable remotely?
Yes, CVE-2025-2469 is remotely exploitable as it allows unauthenticated users access to sensitive data.