CVE-2025-2498: Insufficient Granularity of Access Control in GitLab
An improper access control in Gitlab EE affecting all versions from 12.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that under certain conditions could have allowed users to view assigned issues from restricted groups by bypassing IP restrictions.
Other sources
GitLab has remediated an issue that under certain conditions could have allowed users to view assigned issues from restricted groups by bypassing IP restrictions.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-2498?
CVE-2025-2498 has a moderate severity rating due to improper access control allowing users to view restricted group issues.
How do I fix CVE-2025-2498?
To address CVE-2025-2498, update GitLab EE to version 18.0.6 or later, or 18.1.4 or later, or 18.2.2 or later.
What versions are affected by CVE-2025-2498?
CVE-2025-2498 affects all GitLab EE versions from 12.0 to 18.0.6, 18.1 to 18.1.4, and 18.2 to 18.2.2.
Who is impacted by CVE-2025-2498?
Users of GitLab EE who have restricted groups may be impacted by CVE-2025-2498 due to the ability to bypass IP restrictions.
What types of access does CVE-2025-2498 exploit?
CVE-2025-2498 exploits improper access control, allowing unauthorized viewing of assigned issues within restricted groups.