← Back

CVE-2025-11340

nvd nist
Published: Oct 9, 2025Modified: Oct 20, 2025

JSON object

Loading...
7.7
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
Exploitability: 3.1 / Impact: 4.0
Source: cve@gitlab.com (Secondary)

Description

GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 to 18.3.4, 18.4 to 18.4.2 that, under certain conditions, could have allowed authenticated users with read-only API tokens to perform unauthorized write operations on vulnerability records by exploiting incorrectly scoped GraphQL mutations.

Affected (4)

Products: Gitlab: Gitlab
1 product
Gitlab
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Gitlab
From 18.3.0 to 18.3.4
From 18.4.0 to 18.4.2
From 18.3.0 to 18.3.4
From 18.4.0 to 18.4.2

References (2)

Timeline

No history available yet.