An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that could have allowed Guest users to access sensitive information stored in virtual registry configurations.
References
Link | Resource |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/567777 | Broken Link |
https://hackerone.com/reports/3323573 | Permissions Required |
Configurations
Configuration 1 (hide)
|
History
29 Sep 2025, 13:10
Type | Values Removed | Values Added |
---|---|---|
References | () https://gitlab.com/gitlab-org/gitlab/-/issues/567777 - Broken Link | |
References | () https://hackerone.com/reports/3323573 - Permissions Required | |
CPE | cpe:2.3:a:gitlab:gitlab:18.4.0:*:*:*:enterprise:*:*:* cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* cpe:2.3:a:gitlab:gitlab:18.4.0:*:*:*:community:*:*:* cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* |
|
First Time |
Gitlab gitlab
Gitlab |
26 Sep 2025, 09:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-26 09:15
Updated : 2025-09-29 13:10
NVD link : CVE-2025-9958
Mitre link : CVE-2025-9958
CVE.ORG link : CVE-2025-9958
JSON object : View
Products Affected
gitlab
- gitlab
CWE
CWE-201
Insertion of Sensitive Information Into Sent Data