VDB
CVE-2025-11340
CVE-2025-11340
PUBLISHED
GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 to 18.3.4, 18.4 to 18.4.2 that, under certain conditions, could have allowed authenticated users with read-only API tokens to perform unauthorized write operations on vulnerability records by exploiting incorrectly scoped GraphQL mutations.
EPSS 0.01% · 2.8th percentile
Risk Scores
EPSS Score
0.01%
2.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | gitlab | 18.3.0, 18.4.0 |
| Bitnami | gitlab | 18.3.0, 18.4.0 |
Timeline
- Jan 21, 1970 Security Advisory
- Oct 9, 2025 CVE Published
- Oct 9, 2025 Coalition ESS Score
- Oct 10, 2025 EPSS Score
- Oct 10, 2025 Coalition ESS Score
- Oct 11, 2025 Coalition ESS Score
- Oct 16, 2025 EPSS Score
- Oct 16, 2025 Coalition ESS Score
- Oct 20, 2025 Coalition ESS Score
- Oct 23, 2025 EPSS Score
- Oct 29, 2025 EPSS Score
- Nov 4, 2025 EPSS Score