Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-1977 | An insecure direct object reference vulnerability in GitLab EE affecting all versions from 15.7 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to view repositories in an unauthorized way. |
Solution
Upgrade to versions 17.6.5, 17.7.4, 17.8.2 or above.
Workaround
No workaround given by the vendor.
Thu, 07 Aug 2025 04:00:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* |
Sat, 12 Jul 2025 22:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 11 Jul 2025 22:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 13 Feb 2025 01:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Feb 2025 00:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An insecure direct object reference vulnerability in GitLab EE affecting all versions from 15.7 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to view repositories in an unauthorized way. | |
| Title | Files or Directories Accessible to External Parties in GitLab | |
| First Time appeared |
Gitlab
Gitlab gitlab |
|
| Weaknesses | CWE-552 | |
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gitlab
Gitlab gitlab |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2025-02-12T15:12:26.513Z
Reserved: 2025-02-04T20:30:41.930Z
Link: CVE-2025-1042
Updated: 2025-02-12T15:12:14.980Z
Status : Analyzed
Published: 2025-02-12T15:15:16.230
Modified: 2025-08-06T18:48:24.110
Link: CVE-2025-1042
No data.
OpenCVE Enrichment
No data.
EUVD