CVE-2025-2045
CVE-2025-2045
Título es
CVE-2025-2045
Jue, 06/03/2025 – 13:15
Tipo
CWE-863
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2025-2045
Descripción en
Improper authorization in GitLab EE affecting all versions from 17.7 prior to 17.7.6, 17.8 prior to 17.8.4, 17.9 prior to 17.9.1 allow users with limited permissions to access to potentially sensitive project analytics data.
06/03/2025
06/03/2025
Vector CVSS:3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Gravedad 3.1 (CVSS 3.1 Base Score)
4.30
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
MEDIUM
Referencias
https://gitlab.com/gitlab-org/gitlab/-/issues/512050
https://hackerone.com/reports/2921111
Enviar en el boletín
Off
