GitLab EE Improper Access Control Vulnerability Allowing Issue View Bypass

Vulnerability

A vulnerability exists in GitLab EE versions 12.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2, where improper access control could have allowed users to view assigned issues from restricted groups by bypassing IP restrictions under certain conditions.

Impact

Exploitation of this vulnerability could lead to unauthorized access to issue data from restricted groups.

Added: Aug 13, 2025, 9:37 PM
Updated: Aug 13, 2025, 9:37 PM

Vulnerability Rating

Custom Algorithm
spread
7.3
impact
2.5
exploitability
4.8
remediation
0.0
relevance
0.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.