
Severity
Medium
Analysis Summary
CVE-2025-0652 CVSS:4.3
GitLab could allow a remote authenticated attacker to obtain sensitive information, caused by incorrect authorization.
CVE-2025-2045 CVSS:4.3
GitLab could allow a remote authenticated attacker to obtain sensitive information, caused by improper authorization.
Impact
- Information Disclosure
Indicators of Compromise
CVE
CVE-2025-0652
CVE-2025-2045
Affected Vendors
- GitLab
Affected Products
- GitLab - 17.9
- GitLab - 16.9
- GitLab - 17.8
- GitLab - 17.7.0
Remediation
Upgrade to the latest version of GitLab, available from the GitLab Website.