CVE-2025-6769: Exposure of Sensitive System Information to an Unauthorized Control Sphere in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions from 15.1 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed authenticated users to view administrator-only maintenance notes by accessing runner details through specific interfaces.
Other sources
GitLab has remediated an issue that could have allowed authenticated users to view administrator-only maintenance notes by accessing runner details through specific interfaces.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-6769?
CVE-2025-6769 has a medium severity rating due to its potential to expose sensitive information to authenticated users.
How do I fix CVE-2025-6769?
To fix CVE-2025-6769, upgrade your GitLab CE/EE installation to version 18.1.6 or later, or 18.2.6, or 18.3.2.
What versions are affected by CVE-2025-6769?
CVE-2025-6769 affects GitLab CE/EE versions from 15.1 to 18.1.6, 18.2 to 18.2.6, and 18.3 to 18.3.2.
Who can exploit CVE-2025-6769?
CVE-2025-6769 can be exploited by authenticated users who have access to specific runner details in GitLab.
What data is exposed by CVE-2025-6769?
CVE-2025-6769 allows authenticated users to view administrator-only maintenance notes that should be restricted.