← Back

CVE-2025-2242

nvd nist
Published: Mar 27, 2025Modified: Aug 13, 2025

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

An improper access control vulnerability in GitLab CE/EE affecting all versions from 17.4 prior to 17.8.6, 17.9 prior to 17.9.3, and 17.10 prior to 17.10.1 allows a user who was an instance admin before but has since been downgraded to a regular user to continue to maintain elevated privileges to groups and projects.

Affected (6)

Products: Gitlab: Gitlab
1 product
Gitlab
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Gitlab
From 17.4.0 to 17.8.6
From 17.9.0 to 17.9.3
From 17.4.0 to 17.8.6
From 17.9.0 to 17.9.3
Version 17.10.0
Version 17.10.0

References (1)

Timeline

No history available yet.