GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 prior to 18.4.5, 18.5 prior to 18.5.3, and 18.6 prior to 18.6.1 that could have allowed an authenticated user to obtain…
High CVSS 7.7
Summary
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 prior to 18.4.5, 18.5 prior to 18.5.3, and 18.6 prior to 18.6.1 that could have allowed an authenticated user to obtain credentials from higher-privileged users and perform actions in their context under specific conditions.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://about.gitlab.com/releases/2025/11/26/patch-release-gitlab-18-6-1-released/
- https://gitlab.com/gitlab-org/gitlab/-/issues/494478 Broken Link
- https://hackerone.com/reports/2707421 Third Party Advisory
Timeline
- nvd_ingest NVD