PT-2025-29072 · Gitlab · Gitlab Ce/Ee

Published

2025-07-09

·

Updated

2025-07-25

·

CVE-2025-4972

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: GitLab EE versions prior to 18.0.4 GitLab EE versions prior to 18.1.2
Description: An issue allows authenticated users with invitation privileges to bypass group-level user invitation restrictions by manipulating group invitation functionality.
Recommendations: Update GitLab EE to version 18.0.4 or later. Update GitLab EE to version 18.1.2 or later.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2025-09095
BIT-GITLAB-2025-4972
CVE-2025-4972

Affected Products

Gitlab Ce/Ee