PT-2025-13173 · Gitlab · Gitlab Ce/Ee

Publicado

2025-03-12

·

Atualizado

2025-08-13

·

CVE-2025-2242

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 17.4 through 17.8.6 GitLab CE/EE versions 17.9 through 17.9.3 GitLab CE/EE versions 17.10 through 17.10.1
Description The issue is related to an improper access control, allowing a user who was previously an instance admin but has since been downgraded to a regular user to maintain elevated privileges to groups and projects.
Recommendations For versions 17.4 through 17.8.6, update to version 17.8.6 or later. For versions 17.9 through 17.9.3, update to version 17.9.3 or later. For versions 17.10 through 17.10.1, update to version 17.10.1 or later.

Exploit

Correção

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-03515
BIT-GITLAB-2025-2242
CVE-2025-2242

Produtos afetados

Gitlab Ce/Ee