All intelligence
// vulnerability record
live · NVDCVE-2025-0652
MEDIUMpublished 2025-03-13 06:15 UTC · 1 year ago · modified 2026-06-17 08:26 UTC
4.3
CVSS / 10
// description
An issue has been discovered in GitLab EE/CE affecting all versions starting from 16.9 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2 could allow unauthorized users to access confidential information intended for internal use only.
// cvss 3.1 vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
// weaknesses (CWE)
- CWE-863