VDB
CVE-2025-6168
CVE-2025-6168
PUBLISHED
CVSS 2.700000047683716 LOW
An issue has been discovered in GitLab EE affecting all versions from 18.0 before 18.0.4 and 18.1 before 18.1.2 that could have allowed authenticated maintainers to bypass group-level user invitation restrictions by sending crafted API requests.
EPSS 0.32% · 25.1th percentile
Risk Scores
CVSS 3.1
2.700000047683716
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
EPSS Score
0.32%
25.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | gitlab | 18.0.0 |
| Bitnami | gitlab | 18.0.0 |
Timeline
- Jan 21, 1970 Security Advisory
- Jul 9, 2025 CVE Published
- Jul 10, 2025 EPSS Score
- Jul 20, 2025 EPSS Score
- Jul 29, 2025 EPSS Score
- Aug 8, 2025 EPSS Score
- Aug 17, 2025 EPSS Score
- Aug 27, 2025 EPSS Score
- Sep 6, 2025 EPSS Score
- Sep 15, 2025 EPSS Score
- Sep 25, 2025 EPSS Score
- Oct 5, 2025 EPSS Score