CVE-2025-6168
—CVSS 3.1
2.7 low
EPSS
<1%p25
Published
()
Modified
Description
An issue has been discovered in GitLab EE affecting all versions from 18.0 before 18.0.4 and 18.1 before 18.1.2 that could have allowed authenticated maintainers to bypass group-level user invitation restrictions by sending crafted API requests.
- Vendors
- gitlab
- Products
- gitlab
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.