CVE-2025-5819: Incorrect Permission Assignment for Critical Resource in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions from 15.7 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authenticated users with developer access to obtain ID tokens for protected branches under certain circumstances.
Other sources
GitLab has remediated an issue that could have allowed authenticated users with developer access to obtain ID tokens for protected branches under certain circumstances.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-5819?
CVE-2025-5819 is considered a medium severity vulnerability as it allows authenticated users with developer access to obtain ID tokens for protected branches.
How do I fix CVE-2025-5819?
To remediate CVE-2025-5819, upgrade GitLab to versions 17.11.6, 18.0.4, or 18.1.2 or later.
Who is affected by CVE-2025-5819?
CVE-2025-5819 affects all versions of GitLab CE/EE from 15.7 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2.
What can attackers do with CVE-2025-5819?
Attackers exploiting CVE-2025-5819 can gain unauthorized access to ID tokens for protected branches through legitimate developer accounts.
Is there a workaround for CVE-2025-5819 until a fix is applied?
Currently, there are no specific workarounds for CVE-2025-5819; it is recommended to update to the patched versions as soon as possible.