An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that could have allowed Guest users to access sensitive information stored in virtual registry configurations.
Metrics
Affected Vendors & Products
Fixes
Solution
Upgrade to version 18.2.7, 18.3.3 or 18.4.1 or above.
Workaround
No workaround given by the vendor.
References
History
Fri, 26 Sep 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 26 Sep 2025 09:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that could have allowed Guest users to access sensitive information stored in virtual registry configurations. | |
Title | Insertion of Sensitive Information Into Sent Data in GitLab | |
First Time appeared |
Gitlab
Gitlab gitlab |
|
Weaknesses | CWE-201 | |
CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | |
Vendors & Products |
Gitlab
Gitlab gitlab |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2025-09-26T13:15:46.097Z
Reserved: 2025-09-03T16:05:58.242Z
Link: CVE-2025-9958

Updated: 2025-09-26T13:15:43.189Z

Status : Awaiting Analysis
Published: 2025-09-26T09:15:49.180
Modified: 2025-09-26T14:32:19.853
Link: CVE-2025-9958

No data.

No data.