Description
An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. An attacker may be able to reveal masked or hidden CI variables (that they did not author) in the WebUI, by simply creating their own variable and observing the HTTP response.
INFO
Published Date :
2025-05-22T13:30:28.496Z
Last Modified :
2025-05-22T14:21:32.253Z
Source :
GitLab
AFFECTED PRODUCTS
The following products are affected by CVE-2025-4979 vulnerability.
| Vendors | Products |
|---|---|
| Gitlab |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-4979.
| URL | Resource |
|---|---|
| https://gitlab.com/gitlab-org/gitlab/-/issues/524455 |
|
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact