CVE-2025-5121

Published Jun 20, 2025

Last updated 24 days ago

Overview

Description
An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.4 and 18.0 before 18.0.2. A missing authorization check may have allowed compliance frameworks to be applied to projects outside the compliance framework's group.
Source
cve@gitlab.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.5
Impact score
6
Exploitability score
1.8
Vector string
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Severity
HIGH

Weaknesses

cve@gitlab.com
CWE-862

Social media

Hype score
Not currently trending
  1. CVE-2025-5121 An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.4 and 18.0 before 18.0.2. A missing authorization check may have allowed com… https://t.co/rXXvF4gqb8

    @CVEnew

    21 Jun 2025

    227 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. [CVE-2025-5121: HIGH] GitLab CE/EE versions 17.11 prior to 17.11.4 & 18.0 prior to 18.0.2 have a vulnerability allowing unauthorized application of compliance frameworks to projects, impacting cyber security.#cve,CVE-2025-5121,#cybersecurity https://t.co/9Qj9XA3RCP https://t.

    @CveFindCom

    20 Jun 2025

    53 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 GitLab opravuje závažnou zranitelnost, která umožňuje převzetí cizích účtů. Šlo o HTML injection, kdy mohl útočník vložit škodlivý script do vyhledávacího pole. Poslední aktualizace mimo jiné opravuje i řadu dalších chyb včetně zranitelnosti CVE-2

    @AlefSecurity

    14 Jun 2025

    75 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. 🗞️ GitLab has patched high-severity vulnerabilities, including an HTML injection flaw (CVE-2025-4278) that allows account takeovers and a missing authentication issue (CVE-2025-5121) that enables malicious CI/CD job injections. Admins are urged to upgrade. Key takeaways:

    @gossy_84

    13 Jun 2025

    67 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. GitLab has released security patches for versions 18.0.2, 17.11.4, and 17.10.8 to fix critical vulnerabilities, including account takeover via HTML injection (CVE-2025-4278) and malicious CI/CD job injections (CVE-2025-5121). Stay updated! 🔒 #GitLab #Se… https://t.co/vGyM6jK

    @TweetThreatNews

    12 Jun 2025

    97 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes