PT-2025-33048 · Gitlab · Gitlab Ce/Ee

Published

2025-03-18

·

Updated

2025-08-18

·

CVE-2025-2498

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: GitLab EE versions 12.0 through 18.0.5 GitLab EE versions 18.1 through 18.1.3 GitLab EE versions 18.2 through 18.2.1
Description: An improper access control issue exists in GitLab EE. Under certain conditions, users could view assigned issues from restricted groups by bypassing IP restrictions.
Recommendations: Update GitLab EE to version 18.0.6 or later. Update GitLab EE to version 18.1.4 or later. Update GitLab EE to version 18.2.2 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-10980
BIT-GITLAB-2025-2498
CVE-2025-2498

Affected Products

Gitlab Ce/Ee