CVE-2025-6171: Missing Authorization in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker with reporter access to view branch names and pipeline details by accessing the packages API endpoint even when repository access was disabled.
Other sources
GitLab has remediated an issue that could have allowed an authenticated user with reporter access to view branch names and pipeline details by accessing the packages API endpoint even when repository access was disabled.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-6171?
CVE-2025-6171 has been rated as a moderate severity vulnerability.
How do I fix CVE-2025-6171?
To remediate CVE-2025-6171, upgrade GitLab to versions 18.3.6, 18.4.4, or 18.5.2 or later.
What versions of GitLab are affected by CVE-2025-6171?
CVE-2025-6171 affects GitLab CE/EE versions from 13.2 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2.
Who can exploit CVE-2025-6171?
CVE-2025-6171 can be exploited by an authenticated attacker with reporter access.
What data can be exposed due to CVE-2025-6171?
CVE-2025-6171 allows an attacker to view branch names and pipeline details via the packages API.