CVE-2025-8770: Authorization Bypass Through User-Controlled Key in GitLab
An issue has been discovered in GitLab EE affecting all versions from 18.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that could have allowed authenticated users with specific access to bypass merge request approval policies by manipulating approval rule identifiers.
Other sources
GitLab has remediated an issue that could have allowed authenticated users with specific access to bypass merge request approval policies by manipulating approval rule identifiers.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-8770?
CVE-2025-8770 is classified as a medium severity vulnerability.
How do I fix CVE-2025-8770?
To fix CVE-2025-8770, upgrade GitLab EE to version 18.0.6, 18.1.4, or 18.2.2 or later.
What types of users are affected by CVE-2025-8770?
Authenticated users with specific access rights can exploit CVE-2025-8770.
What impacts could CVE-2025-8770 have on GitLab EE?
CVE-2025-8770 could allow users to bypass merge request approval policies, leading to potential unauthorized changes.
Which versions of GitLab EE are vulnerable to CVE-2025-8770?
All versions of GitLab EE from 18.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 are affected by CVE-2025-8770.