GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.3, and 18.5 before 18.5.1 that under certain conditions could have allowed authenticated users to gain unauthorized project access by exploiting the access request approval workflow.
                
            Metrics
Affected Vendors & Products
References
        History
                    Tue, 28 Oct 2025 16:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Tue, 28 Oct 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| CPEs | cpe:2.3:a:gitlab:gitlab:18.5.0:*:*:*:community:*:*:* | 
Tue, 28 Oct 2025 13:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* cpe:2.3:a:gitlab:gitlab:18.5.0:*:*:*:community:*:*:* cpe:2.3:a:gitlab:gitlab:18.5.0:*:*:*:enterprise:*:*:* | 
Mon, 27 Oct 2025 00:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.3, and 18.5 before 18.5.1 that under certain conditions could have allowed authenticated users to gain unauthorized project access by exploiting the access request approval workflow. | |
| Title | Business Logic Errors in GitLab | |
| First Time appeared | Gitlab Gitlab gitlab | |
| Weaknesses | CWE-840 | |
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | |
| Vendors & Products | Gitlab Gitlab gitlab | |
| References |  | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: GitLab
Published: 2025-10-27T00:06:04.304Z
Updated: 2025-10-28T15:18:04.225Z
Reserved: 2025-06-25T03:30:45.511Z
Link: CVE-2025-6601
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-10-28T15:17:56.420Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2025-10-27T00:15:41.100
Modified: 2025-10-28T13:38:59.890
Link: CVE-2025-6601
 Redhat
                        Redhat
                    No data.