CVE-2025-5846
BaseFortify
Publication date: 2025-06-26
Last updated on: 2025-08-12
Assigner: GitLab Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| gitlab | gitlab | From 16.10.0 (inc) to 17.11.5 (exc) |
| gitlab | gitlab | From 18.0.0 (inc) to 18.0.3 (exc) |
| gitlab | gitlab | 18.1.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in GitLab EE allows authenticated users to assign unrelated compliance frameworks to projects by sending specially crafted GraphQL mutations. It bypasses the usual permission checks that are specific to each compliance framework.
How can this vulnerability impact me? :
The vulnerability could lead to improper assignment of compliance frameworks to projects, potentially causing confusion or misrepresentation of compliance status. However, it has a low severity score and does not impact confidentiality or availability, only integrity to a limited extent.