Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Brian Williams

Researcher fromGitLab
#36275of 56,331
7.7Total CVSS
Vulnerabilities · 1
PT-2025-41364
7.7
2025-10-08
Gitlab · Gitlab Ce/Ee · CVE-2025-11340
**Name of the Vulnerable Software and Affected Versions** GitLab EE versions 18.3 through 18.3.4 GitLab EE versions 18.4 through 18.4.2 **Description** An authorization issue exists in the GitLab EE GraphQL API. Incorrectly scoped GraphQL mutations could allow authenticated users with read-only API tokens to perform unauthorized write operations on vulnerability records under certain conditions. The issue allows for unauthorized modification of vulnerability data. **Recommendations** Update GitLab EE from versions 18.3 through 18.3.4 to a newer, fixed version. Update GitLab EE from versions 18.4 through 18.4.2 to a newer, fixed version.