VDB
CVE-2025-3396
CVE-2025-3396
PUBLISHED
CVSS 4.300000190734863 MEDIUM
An issue has been discovered in GitLab EE affecting all versions from 13.3 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that could have allowed authenticated project owners to bypass group-level forking restrictions by manipulating API requests.
EPSS 0.32% · 24.0th percentile
Risk Scores
CVSS 3.1
4.300000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS Score
0.32%
24.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | gitlab | 18.1.0, 13.3.0 |
| Bitnami | gitlab | 13.3.0, 18.1.0 |
Timeline
- Jul 9, 2025 CVE Published
- Jul 10, 2025 EPSS Score
- Jul 10, 2025 Coalition ESS Score
- Jul 10, 2025 PoC Published
- Jul 10, 2025 CVE Updated
- Jul 20, 2025 EPSS Score
- Jul 25, 2025 Coalition ESS Score
- Jul 29, 2025 EPSS Score
- Aug 8, 2025 EPSS Score
- Aug 17, 2025 EPSS Score
- Aug 22, 2025 Coalition ESS Score
- Aug 26, 2025 Coalition ESS Score