VDB

CVE-2025-2242

CVE-2025-2242 PUBLISHED

An improper access control vulnerability in GitLab CE/EE affecting all versions from 17.4 prior to 17.8.6, 17.9 prior to 17.9.3, and 17.10 prior to 17.10.1 allows a user who was an instance admin before but has since been downgraded to a regular user to continue to maintain elevated privileges to groups and projects.

EPSS 0.03% · 7.9th percentile

Risk Scores

EPSS Score
0.03%
7.9th percentile

Affected Products

VendorProductVersions
Bitnamigitlab17.4.0
Bitnamigitlab17.4.0

Timeline

  • Mar 26, 2025 CVE Published
  • Mar 27, 2025 PoC Published
  • Mar 27, 2025 PoC Published
  • Mar 28, 2025 EPSS Score
  • Mar 28, 2025 Coalition ESS Score
  • Apr 4, 2025 PoC Published
  • Apr 10, 2025 EPSS Score
  • Apr 23, 2025 EPSS Score
  • May 6, 2025 EPSS Score
  • May 19, 2025 EPSS Score
  • Jun 1, 2025 EPSS Score
  • Jun 14, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›