PT-2025-6843 · Gitlab · Gitlab Ce/Ee

Published

2025-02-12

·

Updated

2025-02-17

·

CVE-2025-1198

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 16.11 through 17.6.4 GitLab CE/EE versions 17.7 through 17.7.3 GitLab CE/EE versions 17.8 through 17.8.1
Description An issue in GitLab CE/EE meant that long-lived connections in ActionCable potentially allowed revoked Personal Access Tokens access to streaming results.
Recommendations For versions 16.11 through 17.6.4, update to version 17.6.5 or later. For versions 17.7 through 17.7.3, update to version 17.7.4 or later. For versions 17.8 through 17.8.1, update to version 17.8.2 or later.

Exploit

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-05389
BIT-GITLAB-2025-1198
CVE-2025-1198

Affected Products

Gitlab Ce/Ee