PT-2025-15987 · Gitlab · Gitlab Ce/Ee

Ap-Wtioit

·

Published

2025-04-09

·

Updated

2025-08-07

·

CVE-2025-2469

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: GitLab CE/EE versions 17.9 through 17.9.5 GitLab CE/EE versions 17.10 through 17.10.3
Description: An issue exists in GitLab Community Edition (CE) and Enterprise Edition (EE) where runtime profiling data of a specific service was accessible to unauthenticated users. This allows potential unauthorized access to information.
Recommendations: GitLab CE/EE versions 17.9 through 17.9.5: Upgrade to version 17.9.6 or later. GitLab CE/EE versions 17.10 through 17.10.3: Upgrade to version 17.10.4 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-04562
BIT-GITLAB-2025-2469
CVE-2025-2469

Affected Products

Gitlab Ce/Ee