VDB

CVE-2025-6168

CVE-2025-6168 PUBLISHED CVSS 2.700000047683716 LOW

An issue has been discovered in GitLab EE affecting all versions from 18.0 before 18.0.4 and 18.1 before 18.1.2 that could have allowed authenticated maintainers to bypass group-level user invitation restrictions by sending crafted API requests.

EPSS 0.32% · 25.1th percentile

Risk Scores

CVSS 3.1
2.700000047683716
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
EPSS Score
0.32%
25.1th percentile

Affected Products

VendorProductVersions
Bitnamigitlab18.0.0
Bitnamigitlab18.0.0

Timeline

  • Jan 21, 1970 Security Advisory
  • Jul 9, 2025 CVE Published
  • Jul 10, 2025 EPSS Score
  • Jul 20, 2025 EPSS Score
  • Jul 29, 2025 EPSS Score
  • Aug 8, 2025 EPSS Score
  • Aug 17, 2025 EPSS Score
  • Aug 27, 2025 EPSS Score
  • Sep 6, 2025 EPSS Score
  • Sep 15, 2025 EPSS Score
  • Sep 25, 2025 EPSS Score
  • Oct 5, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›