CVE-2025-1042
Files or Directories Accessible to External Parties in GitLab
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.9EPSS 0.4%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
12 Feb 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An insecure direct object reference vulnerability in GitLab EE affecting all versions from 15.7 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to view repositories in an unauthorized way.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Affected products
GitLab · GitLabWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →