An issue has been discovered in GitLab EE affecting all versions from 17.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that, under certain circumstances, could have allowed an attacker to access internal notes in GitLab Duo responses.
History

Mon, 28 Jul 2025 14:15:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:18.2:*:*:*:enterprise:*:*:*

Thu, 24 Jul 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 24 Jul 2025 06:30:00 +0000

Type Values Removed Values Added
Description An issue has been discovered in GitLab EE affecting all versions from 17.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that, under certain circumstances, could have allowed an attacker to access internal notes in GitLab Duo responses.
Title Exposure of Sensitive Information Due to Incompatible Policies in GitLab
First Time appeared Gitlab
Gitlab gitlab
Weaknesses CWE-213
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published: 2025-07-24T06:05:37.730Z

Updated: 2025-07-24T13:36:32.546Z

Reserved: 2025-05-20T05:15:30.490Z

Link: CVE-2025-4976

cve-icon Vulnrichment

Updated: 2025-07-24T13:35:01.088Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-24T07:15:53.963

Modified: 2025-07-28T14:14:07.687

Link: CVE-2025-4976

cve-icon Redhat

No data.