GitLab EE IP Access Restriction Bypass Vulnerability Allowing Sensitive Information Disclosure

Vulnerability

A vulnerability exists in GitLab EE in versions 12.0 prior to 17.10.8, 17.11 prior to 17.11.4, and 18.0 prior to 18.0.2. Under certain conditions, users could bypass IP access restrictions, potentially leading to unauthorized access to sensitive information.

Impact

Exploitation of this vulnerability could result in unauthorized access to sensitive information by bypassing IP access restrictions.

Added: Jun 12, 2025, 5:24 PM
Updated: Jun 12, 2025, 5:24 PM

Vulnerability Rating

Custom Algorithm
spread
7.3
impact
2.5
exploitability
7.4
remediation
0.0
relevance
0.2
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.