CVE-2025-13874: Authorization Bypass Through User-Controlled Key in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with Guest permissions to view issues in projects they were not authorized to access.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13874?
CVE-2025-13874 is considered a high severity vulnerability due to its potential to allow unauthorized access to sensitive project information.
How do I fix CVE-2025-13874?
To remediate CVE-2025-13874, upgrade GitLab CE/EE to versions 18.9.7, 18.10.6, or 18.11.3 or later.
Who is affected by CVE-2025-13874?
CVE-2025-13874 affects users of GitLab CE and EE from versions 15.1 to 18.9.7, 18.10 to 18.10.6, and 18.11 to 18.11.3.
What can an attacker do with CVE-2025-13874?
An attacker exploiting CVE-2025-13874 could bypass authorization and view issues in projects where they should not have access.
Is there a public report for CVE-2025-13874?
Yes, details on CVE-2025-13874 are documented in public vulnerability reports that describe the nature of the issue.