« Volver al listado

CVE-2025-5195

Estado: AnalizadaMedia (4.3)—

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. It was possible for authenticated users to access arbitrary compliance frameworks, leading to unauthorized data disclosure.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-5195",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-5195",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-06-12T13:22:10.914910Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve@gitlab.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@gitlab.com",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"
          ],
          "repo": "git://git@gitlab.com:gitlab-org/gitlab.git",
          "vendor": "GitLab",
          "product": "GitLab",
          "versions": [
            {
              "status": "affected",
              "version": "17.9",
              "lessThan": "17.10.8",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "17.11",
              "lessThan": "17.11.4",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "18.0",
              "lessThan": "18.0.2",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-06-12T11:15:19.647",
  "references": [
    {
      "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/534960",
      "tags": [
        "Exploit",
        "Issue Tracking"
      ],
      "source": "cve@gitlab.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve@gitlab.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-639"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. It was possible for authenticated users to access arbitrary compliance frameworks, leading to unauthorized data disclosure."
    },
    {
      "lang": "es",
      "value": "Se ha detectado un problema en GitLab CE/EE que afecta a todas las versiones (desde la 17.9 hasta la 17.10.7), la 17.11 hasta la 17.11.3 y la 18.0 hasta la 18.0.1. Los usuarios autenticados podían acceder a frameworks de cumplimiento arbitrarios, lo que provocaba la divulgación no autorizada de datos."
    }
  ],
  "lastModified": "2026-06-17T09:47:25.677",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C7A341DC-6679-4B9F-87FC-18CE5ACB0E44",
              "versionEndExcluding": "17.10.7",
              "versionStartIncluding": "17.9.0"
            },
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FE404772-0AE4-43C4-87A0-2486808CD6F9",
              "versionEndExcluding": "17.10.7",
              "versionStartIncluding": "17.9.0"
            },
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "194F7832-AEB6-4CD4-8CA8-81D8BF1666C9",
              "versionEndExcluding": "17.11.3",
              "versionStartIncluding": "17.11.0"
            },
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "85308EBB-8AB6-4344-9944-D124878DA138",
              "versionEndExcluding": "17.11.3",
              "versionStartIncluding": "17.11.0"
            },
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:18.0.0:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C7F28C32-4C21-4EE4-985C-34BD8C9FE300"
            },
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:18.0.0:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "52187A72-1412-48DE-90DD-2948630CFC19"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@gitlab.com"
}