PoC Index

CVE-2025-2408

MEDIUM 5.3EPSS 0.3%

An issue has been discovered in GitLab CE/EE affecting all versions from 13.12 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions users could bypass IP access restrictions and view sensitive information.

CVSS v3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
0.32% chance of exploitation in the next 30 days, 25th percentile
Published
2025-04-10

Proof-of-concept exploits (1)

References

Related