← Back to CVE List
CVE-2025-7001NVD
Vulnerability Summary
An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed priviledged users to access certain resource_group information through the API which should have been unavailable.
CVSS v3.1 Base Metrics — Score 4.3 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeUnchanged
ConfidentialityLow
IntegrityNone
AvailabilityNone
Affected & Patched Versions
- Gitlab Gitlab >= 15.0.0 and < 18.0.5
- Gitlab Gitlab >= 18.1.0 and < 18.1.3
- Gitlab Gitlab
- Gitlab Gitlab 18.0.5
- Gitlab Gitlab 18.1.3