Exposure of Sensitive Information Due to Incompatible Policies in GitLab

CVE Details

Basic Information

Title Exposure of Sensitive Information Due to Incompatible Policies in GitLab
Type cve
Published 2025-07-24T06:05:37.730Z
Modified 2025-07-24T06:05:37.730Z

Product Information

Vendor GitLab
Product GitLab
Version 17.0

CVSS Information

Base Score 4.3 (MEDIUM)
Attack Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Analysis

AI Description A vulnerability in GitLab EE could allow attackers to access internal notes in GitLab Duo responses under certain conditions. This issue affects multiple versions of GitLab EE and could expose sensitive information.
AI Severity Medium
AI Vendor GitLab
AI Product GitLab EE
AI Version 17.0 before 18.0.5, 18.1 before 18.1.3, 18.2 before 18.2.1

Affected Products

  • GitLab GitLab 17.0
  • GitLab GitLab 18.1
  • GitLab GitLab 18.2

Additional Information

CWE List CWE-213
Source GitLab

Description

An issue has been discovered in GitLab EE affecting all versions from 17.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that, under certain circumstances, could have allowed an attacker to access internal notes in GitLab Duo responses.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.