VDB
CVE-2025-2242
CVE-2025-2242
PUBLISHED
An improper access control vulnerability in GitLab CE/EE affecting all versions from 17.4 prior to 17.8.6, 17.9 prior to 17.9.3, and 17.10 prior to 17.10.1 allows a user who was an instance admin before but has since been downgraded to a regular user to continue to maintain elevated privileges to groups and projects.
EPSS 0.03% · 7.9th percentile
Risk Scores
EPSS Score
0.03%
7.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | gitlab | 17.4.0 |
| Bitnami | gitlab | 17.4.0 |
Timeline
- Mar 26, 2025 CVE Published
- Mar 27, 2025 PoC Published
- Mar 27, 2025 PoC Published
- Mar 28, 2025 EPSS Score
- Mar 28, 2025 Coalition ESS Score
- Apr 4, 2025 PoC Published
- Apr 10, 2025 EPSS Score
- Apr 23, 2025 EPSS Score
- May 6, 2025 EPSS Score
- May 19, 2025 EPSS Score
- Jun 1, 2025 EPSS Score
- Jun 14, 2025 EPSS Score