CVE-2025-2615
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that could have allowed a blocked user to access sensitive information by establishing GraphQL subscriptions through WebSocket connections.
Vendor
Product
CWE
Yayın Tarihi
2025-11-15 08:15:45
Güncelleme
2025-11-19 17:46:27
Source Identifier
cve@gitlab.com
KEV Date Added
-