CVE-2025-0362
Last modified
CVE-2025-0362 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. An issue has been discovered in GitLab CE/EE affecting all versions from 7.7 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions, an attacker could potentially trick users into unintentionally authorizing sensitive actions on their behalf.. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
An issue has been discovered in GitLab CE/EE affecting all versions from 7.7 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions, an attacker could potentially trick users into unintentionally authorizing sensitive actions on their behalf.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gitlab | Gitlab | >= 7.7.0, < 17.8.7 |
| Gitlab | Gitlab | >= 17.9.0, < 17.9.6 |
| Gitlab | Gitlab | >= 17.10.0, < 17.10.4 |
References
- https://hackerone.com/reports/2926425Permissions Required
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-0362?
How severe is CVE-2025-0362?
How do I fix CVE-2025-0362?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-0356NEC Corporation Aterm WX1500HP Ver.1.4.2 and earlier and WX3…7.2
- CVE-2025-0357The WPBookit plugin for WordPress is vulnerable to arbitrary…9.8
- CVE-2025-0358During an annual penetration test conducted on behalf of Axi…8.8
- CVE-2025-0359During an annual penetration test conducted on behalf of Axi…5.5
- CVE-2025-0360During an annual penetration test conducted on behalf of Axi…7.8
- CVE-2025-0361During an annual penetration test conducted on behalf of Axi…5.3
- CVE-2025-0364BigAntSoft BigAnt Server, up to and including version 5.6.06…9.8
- CVE-2025-0365The Jupiter X Core plugin for WordPress is vulnerable to Dir…6.5
- CVE-2025-0366The Jupiter X Core plugin for WordPress is vulnerable to Loc…8.8
- CVE-2025-0367In versions 3.1.0 and lower of the Splunk Supporting Add-on …6.5
- CVE-2025-0368The Banner Garden Plugin for WordPress plugin through 0.1.3 …6.1
- CVE-2025-0369The JetEngine plugin for WordPress is vulnerable to Stored C…6.4
Are you affected by CVE-2025-0362?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
