GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that could have allowed a blocked user to access sensitive information by establishing GraphQL subscriptions through WebSocket connections.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
Upgrade to version 16.X.X, 16.Y.Y or 16.Z.Z
Workaround
No workaround given by the vendor.
References
History
Sat, 15 Nov 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that could have allowed a blocked user to access sensitive information by establishing GraphQL subscriptions through WebSocket connections. | |
| Title | Insertion of Sensitive Information Into Sent Data in GitLab | |
| First Time appeared |
Gitlab
Gitlab gitlab |
|
| Weaknesses | CWE-201 | |
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gitlab
Gitlab gitlab |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2025-11-15T08:04:44.743Z
Reserved: 2025-03-21T17:30:59.615Z
Link: CVE-2025-2615
No data.
Status : Received
Published: 2025-11-15T08:15:45.820
Modified: 2025-11-15T08:15:45.820
Link: CVE-2025-2615
No data.
OpenCVE Enrichment
No data.