CVE-2025-4972: Incorrect Authorization in GitLab
An issue has been discovered in GitLab EE affecting all versions from 18.0 before 18.0.4 and 18.1 before 18.1.2 that could have allowed authenticated users with invitation privileges to bypass group-level user invitation restrictions by manipulating group invitation functionality.
Other sources
GitLab has remediated an issue that could have allowed authenticated users with invitation privileges to bypass group-level user invitation restrictions by manipulating group invitation functionality.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-4972?
CVE-2025-4972 is classified as a moderate severity vulnerability.
How do I fix CVE-2025-4972?
To fix CVE-2025-4972, upgrade GitLab EE to version 18.0.4 or newer, or to version 18.1.2 or newer.
Who is affected by CVE-2025-4972?
CVE-2025-4972 affects all users of GitLab EE versions prior to 18.0.4 and 18.1.2.
What type of vulnerability is CVE-2025-4972?
CVE-2025-4972 is a vulnerability that allows authenticated users to bypass group-level user invitation restrictions.
What versions of GitLab EE are impacted by CVE-2025-4972?
Versions of GitLab EE from 18.0 before 18.0.4 and 18.1 before 18.1.2 are impacted by CVE-2025-4972.