CVE-2025-1540
CVE-2025-1540
Título es
CVE-2025-1540
Jue, 06/03/2025 – 09:15
Tipo
CWE-863
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2025-1540
Descripción en
An issue has been discovered in GitLab CE/EE for Self-Managed and Dedicated instances affecting all versions from 17.5 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2. It was possible for a user added as an External to read and clone internal projects under certain circumstances."
06/03/2025
06/03/2025
Vector CVSS:3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Gravedad 3.1 (CVSS 3.1 Base Score)
3.10
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
LOW
Referencias
https://about.gitlab.com/releases/2025/02/12/patch-release-gitlab-17-8-2-released/#saml-authentication-misconfigures-external-user-attribute
https://gitlab.com/gitlab-org/gitlab/-/issues/512765
Enviar en el boletín
Off
