GitLab CE/EE Access Token Logging Vulnerability

Vulnerability

A vulnerability exists in GitLab Community Edition (CE) and Enterprise Edition (EE) in versions 17.4 prior to 17.5.5, 17.6 prior to 17.6.3, and 17.7 prior to 17.7.1. Under certain conditions, access tokens may have been inadvertently logged during specific API requests, potentially exposing them in the GitLab logs.

Impact

This vulnerability could lead to unauthorized access token exposure in GitLab logs, allowing for potential misuse of the tokens.

Remediation

GitLab has released patch versions 17.7.1, 17.6.3, and 17.5.5, which address this vulnerability. Users are strongly advised to upgrade to one of these versions immediately. Instructions for updating GitLab can be found on the GitLab update page.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
7.3
impact
2.5
exploitability
5.2
remediation
8.3
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.