216.73.217.22

CVE-2025-2498

· Published 13/08/2025 18:15 · Modified 14/08/2025 13:12

Labels: CVE-2025-2498 2025-08-13CVE-2025-2498CWE-1220[email protected]

Essential information

Published
13/08/2025 18:15
Modified
14/08/2025 13:12
Author
Creator
CVSS
3.1 LOW (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

CVSS metrics

Description

An improper access control in Gitlab EE affecting all versions from 12.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that under certain conditions could have allowed users to view assigned issues from restricted groups by bypassing IP restrictions.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
gitlab / gitlab cpe:2.3:a:gitlab:gitlab:*:12.0:*:*:*:*:*:*
gitlab / gitlab cpe:2.3:a:gitlab:gitlab:*:18.0.0-18.0.6:*:*:*:*:*:*
gitlab / gitlab cpe:2.3:a:gitlab:gitlab:*:18.1.0-18.1.4:*:*:*:*:*:*
gitlab / gitlab cpe:2.3:a:gitlab:gitlab:*:18.2.0-18.2.2:*:*:*:*:*:*

References