First published: Thu Apr 10 2025(Updated: )
An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.9.6, and 17.10 before 17.10.4. The runtime profiling data of a specific service was accessible to unauthenticated users.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >17.9<17.9.6 | |
GitLab Enterprise Edition | >17.10<17.10.4 |
Upgrade to version 17.10.4, 17.9.6
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-2469 is considered to be moderate due to the exposure of sensitive runtime profiling data.
To fix CVE-2025-2469, upgrade GitLab CE to version 17.9.6 or higher and GitLab EE to version 17.10.4 or higher.
CVE-2025-2469 affects all versions of GitLab CE from 17.9 before 17.9.6 and GitLab EE from 17.10 before 17.10.4.
CVE-2025-2469 exposed the runtime profiling data of a specific service to unauthenticated users.
Yes, CVE-2025-2469 is remotely exploitable as it allows unauthenticated users access to sensitive data.