CVE-2025-7000: Insertion of Sensitive Information Into Sent Data in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions from 17.6 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that, under specific conditions, could have allowed unauthorized users to view confidential branch names by accessing project issues with related merge requests.
Other sources
GitLab has remdiated an issue in GitLab CE/EE that under specific conditions, could have allowed unauthorized users to view confidential branch names by accessing project issues with related merge requests.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-7000?
CVE-2025-7000 has been classified as a medium severity vulnerability due to its potential to expose confidential information.
How do I fix CVE-2025-7000?
To remediate CVE-2025-7000, update GitLab to version 18.3.6, 18.4.4, or 18.5.2, which contains the necessary patches.
What versions are affected by CVE-2025-7000?
CVE-2025-7000 affects all GitLab versions from 17.6 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2.
What does CVE-2025-7000 expose?
CVE-2025-7000 potentially allows unauthorized users to view confidential branch names through project issues under specific conditions.
Is CVE-2025-7000 present in GitLab CE, EE or both?
CVE-2025-7000 affects both GitLab Community Edition (CE) and GitLab Enterprise Edition (EE).