PT-2025-43143 · Gitlab · Gitlab Ce/Ee

Published

2025-10-22

·

Updated

2025-10-28

·

CVE-2025-6601

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions GitLab EE versions 18.4 through 18.4.2 GitLab EE versions 18.5 through 18.5.0
Description GitLab EE is affected by a business logic error in the access request approval workflow. This issue could allow authenticated users to gain unauthorized project access under certain conditions.
Recommendations Update GitLab EE to version 18.4.3 or later. Update GitLab EE to version 18.5.1 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-14929
BIT-GITLAB-2025-6601
CVE-2025-6601

Affected Products

Gitlab Ce/Ee