CVE-2025-8094: Improper Handling of Permissions issue in project API impacts GitLab CE/EE
GitLab has remediated an issue that under certain conditions could have allowed authenticated users with maintainer privileges to cause denial of service to other users’ CI/CD pipelines by manipulating shared infrastructure resources beyond their intended access level.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-8094?
CVE-2025-8094 is classified as a medium severity vulnerability that could lead to denial of service.
How do I fix CVE-2025-8094?
To mitigate CVE-2025-8094, it is recommended to upgrade to GitLab versions 18.0.7, 18.1.5, or 18.2.3 or later.
Who is affected by CVE-2025-8094?
CVE-2025-8094 affects GitLab users who have maintainer privileges on versions prior to the specified patched versions.
What kind of impact does CVE-2025-8094 have?
CVE-2025-8094 can allow authenticated users to manipulate shared infrastructure resources, leading to denial of service for other users' CI/CD pipelines.
What products are affected by CVE-2025-8094?
GitLab versions 18.0.6, 18.1.4, and 18.2.2 are specifically affected by CVE-2025-8094.