GitLab EE Information Disclosure Vulnerability in Security Reports

Vulnerability

A vulnerability allowing authenticated users to access information from security reports has been identified in GitLab EE. This issue affects all versions from 13.7 prior to 18.4.5, 18.5 prior to 18.5.3, and 18.6 prior to 18.6.1. The vulnerability arises under certain configuration conditions.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive information in security reports.

Added: Nov 26, 2025, 8:19 PM
Updated: Nov 26, 2025, 8:19 PM

Vulnerability Rating

Custom Algorithm
spread
7.3
impact
0.6
exploitability
5.2
remediation
0.0
relevance
1.1
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.