GitLab CE/EE Sensitive Information Disclosure Vulnerability for Guest Users

Vulnerability

A vulnerability exists in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 14.10 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1. This vulnerability could have allowed Guest users to access sensitive information in virtual registry configurations.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive information for Guest users.

Added: Sep 26, 2025, 9:22 AM
Updated: Sep 26, 2025, 2:51 PM

Vulnerability Rating

Custom Algorithm
spread
7.3
impact
2.5
exploitability
7.4
remediation
0.0
relevance
0.6
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.