{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-6601","assignerOrgId":"ceab7361-8a18-47b1-92ba-4d7d25f6715a","state":"PUBLISHED","assignerShortName":"GitLab","dateReserved":"2025-06-25T03:30:45.511Z","datePublished":"2025-10-27T00:06:04.304Z","dateUpdated":"2025-11-24T07:26:31.684Z"},"containers":{"cna":{"affected":[{"cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","product":"GitLab","repo":"git://git@gitlab.com:gitlab-org/gitlab.git","vendor":"GitLab","versions":[{"lessThan":"18.4.3","status":"affected","version":"18.4","versionType":"semver"},{"lessThan":"18.5.1","status":"affected","version":"18.5","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Thanks [mateuszek](https://hackerone.com/mateuszek) and [rhidayahh](https://hackerone.com/rhidayahh) for reporting this vulnerability through our HackerOne bug bounty program"}],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.3, and 18.5 before 18.5.1 that under certain conditions could have allowed authenticated users to gain unauthorized project access by exploiting the access request approval workflow."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":2.7,"baseSeverity":"LOW","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-840","description":"CWE-840: Business Logic Errors","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"ceab7361-8a18-47b1-92ba-4d7d25f6715a","shortName":"GitLab","dateUpdated":"2025-11-24T07:26:31.684Z"},"references":[{"url":"https://about.gitlab.com/releases/2025/10/22/patch-release-gitlab-18-5-1-released/"},{"name":"GitLab Issue #551267","tags":["issue-tracking","permissions-required"],"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/551267"},{"name":"HackerOne Bug Bounty Report #3209641","tags":["technical-description","exploit","permissions-required"],"url":"https://hackerone.com/reports/3209641"}],"solutions":[{"lang":"en","value":"Upgrade to versions 18.4.3, 18.5.1 or above."}],"title":"Business Logic Errors in GitLab"},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-10-28T15:17:52.854652Z","id":"CVE-2025-6601","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-10-28T15:18:04.225Z"}}]}}