ZeroHour

CVE-2025-5819

CVSS 3.1
5.0 medium
EPSS
<1%p14
Published
()
Modified
Description

An issue has been discovered in GitLab CE/EE affecting all versions from 15.7 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authenticated users with developer access to obtain ID tokens for protected branches under certain circumstances.

Vendors
gitlab
Products
gitlab
Weakness
CWE-732
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.