← Back

CVE-2025-2867

nvd nist
Published: Mar 27, 2025Modified: Aug 13, 2025

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

An issue has been discovered in the GitLab Duo with Amazon Q affecting all versions from 17.8 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. A specifically crafted issue could manipulate AI-assisted development features to potentially expose sensitive project data to unauthorized users.

Affected (6)

Products: Gitlab: Gitlab
1 product
Gitlab
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Gitlab
From 17.8.0 to 17.8.6
From 17.9.0 to 17.9.3
From 17.8.0 to 17.8.6
From 17.9.0 to 17.9.3
Version 17.10.0
Version 17.10.0

References (1)

Timeline

No history available yet.