CVE-2025-5069: Incorrect Ownership Assignment in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions from 17.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could have allowed an authenticated user to gain unauthorized access to confidential issues by creating a project with an identical name to the victim's project.
Other sources
GitLab has remediated an issue that could have allowed an authenticated user to gain unauthorized access to confidential issues by creating a project with an identical name, potentially having users transfer sensitive information to the incorrect project.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-5069?
CVE-2025-5069 is classified as a high-severity vulnerability due to potential unauthorized access to confidential issues.
How do I fix CVE-2025-5069?
To fix CVE-2025-5069, ensure that you upgrade GitLab CE or EE to versions 18.2.7, 18.3.3, or 18.4.1 or later.
Who is affected by CVE-2025-5069?
CVE-2025-5069 affects all versions of GitLab CE from 17.10 to before 18.2.7 and GitLab EE from 18.3 to before 18.3.3 and from 18.4 to before 18.4.1.
What type of vulnerability is CVE-2025-5069?
CVE-2025-5069 is an authentication issue that allows an authenticated user to access confidential data erroneously.
Can CVE-2025-5069 be exploited remotely?
CVE-2025-5069 can be exploited by any authenticated user within the affected GitLab instances.