VDB

CVE-2025-11340

CVE-2025-11340 PUBLISHED

GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 to 18.3.4, 18.4 to 18.4.2 that, under certain conditions, could have allowed authenticated users with read-only API tokens to perform unauthorized write operations on vulnerability records by exploiting incorrectly scoped GraphQL mutations.

EPSS 0.01% · 2.8th percentile

Risk Scores

EPSS Score
0.01%
2.8th percentile

Affected Products

VendorProductVersions
Bitnamigitlab18.3.0, 18.4.0
Bitnamigitlab18.3.0, 18.4.0

Timeline

  • Jan 21, 1970 Security Advisory
  • Oct 9, 2025 CVE Published
  • Oct 9, 2025 Coalition ESS Score
  • Oct 10, 2025 EPSS Score
  • Oct 10, 2025 Coalition ESS Score
  • Oct 11, 2025 Coalition ESS Score
  • Oct 16, 2025 EPSS Score
  • Oct 16, 2025 Coalition ESS Score
  • Oct 20, 2025 Coalition ESS Score
  • Oct 23, 2025 EPSS Score
  • Oct 29, 2025 EPSS Score
  • Nov 4, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›