- Description
- GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 to 18.3.4, 18.4 to 18.4.2 that, under certain conditions, could have allowed authenticated users with read-only API tokens to perform unauthorized write operations on vulnerability records by exploiting incorrectly scoped GraphQL mutations.
- Source
- cve@gitlab.com
- NVD status
- Analyzed
- Products
- gitlab
CVSS 3.1
- Type
- Secondary
- Base score
- 7.7
- Impact score
- 4
- Exploitability score
- 3.1
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
- Severity
- HIGH
- cve@gitlab.com
- CWE-863
- Hype score
- Not currently trending
⚠️Vulnerabilidades corregidas en GitLab ❗CVE-2025-11340 ❗CVE-2025-10004 ➡️Más info: https://t.co/RC82OnN2Dr https://t.co/BdUoPyPIQt
@CERTpy
14 Oct 2025
87 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-11340 pertains to a security flaw in GitLab Enterprise Edition (EE) that affects specific versions (18.3 to 18.3.4 and 18.4 to 18.4.2). The vulnerability arises from improperly scoped GraphQL mutations, which, under certain conditions, could allow authenticated users
@CveTodo
9 Oct 2025
32 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-11340 GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 to 18.3.4, 18.4 to 18.4.2 that, under certain conditions, could have allowed authenticate… https://t.co/JC2L21jSUm
@CVEnew
9 Oct 2025
329 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-11340, CVE-2025-10004, and other: Multiple vulns in GitLab, 4.3 - 7.7 rating❗️ In a recent bulletin, GitLab reported four vulns, including Missing Authorization, DoS, and Incorrect Authorization. Search at https://t.co/hv7QKSqxTR: 👉 Link: https://t.co/2ThlzQ9kRH
@Netlas_io
9 Oct 2025
437 Impressions
0 Retweets
3 Likes
2 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
"matchCriteriaId": "536C1DFE-B81E-4E5E-A979-EBB8AEB62F4C",
"versionEndExcluding": "18.3.4",
"versionStartIncluding": "18.3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
"matchCriteriaId": "15A762DA-E645-404C-B831-A63171FF3EF2",
"versionEndExcluding": "18.3.4",
"versionStartIncluding": "18.3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
"matchCriteriaId": "A0684F06-FCCA-400A-AB87-BB9B9F906187",
"versionEndExcluding": "18.4.2",
"versionStartIncluding": "18.4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
"matchCriteriaId": "719CBD84-A5F7-4332-8C37-D68474A2FB70",
"versionEndExcluding": "18.4.2",
"versionStartIncluding": "18.4.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]