An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed priviledged users to access certain resource_group information through the API which should have been unavailable.
Metrics
Affected Vendors & Products
References
History
Mon, 28 Jul 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* cpe:2.3:a:gitlab:gitlab:18.2:*:*:*:community:*:*:* cpe:2.3:a:gitlab:gitlab:18.2:*:*:*:enterprise:*:*:* |
Thu, 24 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 24 Jul 2025 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed priviledged users to access certain resource_group information through the API which should have been unavailable. | |
| Title | Insufficient Granularity of Access Control in GitLab | |
| First Time appeared |
Gitlab
Gitlab gitlab |
|
| Weaknesses | CWE-1220 | |
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gitlab
Gitlab gitlab |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitLab
Published: 2025-07-24T06:05:22.870Z
Updated: 2025-07-24T13:36:37.546Z
Reserved: 2025-07-02T07:03:01.723Z
Link: CVE-2025-7001
Updated: 2025-07-24T13:35:02.426Z
Status : Analyzed
Published: 2025-07-24T07:15:54.580
Modified: 2025-07-28T14:36:43.487
Link: CVE-2025-7001
No data.