PT-2025-5687 · Gitlab · Gitlab Ce/Ee

Yvvdwf

·

Published

2024-08-07

·

Updated

2025-08-06

·

CVE-2024-6356

CVSS v3.1

4.4

Medium

VectorAV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions GitLab EE versions 16.0 through 17.0.6 GitLab EE versions 17.1 through 17.1.4 GitLab EE versions 17.2 through 17.2.2
Description An issue was discovered in GitLab EE which allowed cross project access for Security policy bot.
Recommendations For GitLab EE versions 16.0 through 17.0.6, update to version 17.0.6 or later. For GitLab EE versions 17.1 through 17.1.4, update to version 17.1.4 or later. For GitLab EE versions 17.2 through 17.2.2, update to version 17.2.2 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-02319
BIT-GITLAB-2024-6356
CVE-2024-6356

Affected Products

Gitlab Ce/Ee