CVE-2025-5069
BaseFortify
Publication date: 2025-09-26
Last updated on: 2025-09-29
Assigner: GitLab Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| gitlab | gitlab | From 17.10.0 (inc) to 18.2.7 (exc) |
| gitlab | gitlab | From 17.10.0 (inc) to 18.2.7 (exc) |
| gitlab | gitlab | From 18.3.0 (inc) to 18.3.3 (exc) |
| gitlab | gitlab | From 18.3.0 (inc) to 18.3.3 (exc) |
| gitlab | gitlab | 18.4.0 |
| gitlab | gitlab | 18.4.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-708 | The product assigns an owner to a resource, but the owner is outside of the intended control sphere. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in GitLab CE/EE allows an authenticated user to gain unauthorized access to confidential issues by creating a project with the same name as another user's project. This means that by duplicating the project name, the attacker could view confidential information they should not have access to.
How can this vulnerability impact me? :
The vulnerability could lead to unauthorized disclosure of confidential information within GitLab projects. If exploited, an attacker could access sensitive issues that are meant to be private, potentially leading to information leaks and compromising project confidentiality.