GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.3, and 18.5 before 18.5.1 that under certain conditions could have allowed authenticated users to gain unauthorized project access by exploiting the access request approval workflow.
Metrics
Affected Vendors & Products
References
History
Tue, 28 Oct 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 28 Oct 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:gitlab:gitlab:18.5.0:*:*:*:community:*:*:* |
Tue, 28 Oct 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* cpe:2.3:a:gitlab:gitlab:18.5.0:*:*:*:community:*:*:* cpe:2.3:a:gitlab:gitlab:18.5.0:*:*:*:enterprise:*:*:* |
Mon, 27 Oct 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.3, and 18.5 before 18.5.1 that under certain conditions could have allowed authenticated users to gain unauthorized project access by exploiting the access request approval workflow. | |
| Title | Business Logic Errors in GitLab | |
| First Time appeared |
Gitlab
Gitlab gitlab |
|
| Weaknesses | CWE-840 | |
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gitlab
Gitlab gitlab |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitLab
Published: 2025-10-27T00:06:04.304Z
Updated: 2025-10-28T15:18:04.225Z
Reserved: 2025-06-25T03:30:45.511Z
Link: CVE-2025-6601
Updated: 2025-10-28T15:17:56.420Z
Status : Analyzed
Published: 2025-10-27T00:15:41.100
Modified: 2025-10-28T13:38:59.890
Link: CVE-2025-6601
No data.