CVE Vulnerabilities

CVE-2025-0194

Insertion of Sensitive Information into Externally-Accessible File or Directory

Published: Jan 08, 2025 | Modified: Jul 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
NEGLIGIBLE
root.io logo minimus.io logo echo.ai logo

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.4 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. Under certain conditions, access tokens may have been logged when API requests were made in a specific manner.

Weakness

The product places sensitive information into files or directories that are accessible to actors who are allowed to have access to the files, but not to the sensitive information.

Affected Software

NameVendorStart VersionEnd Version
GitlabGitlab17.4.0 (including)17.5.5 (excluding)
GitlabGitlab17.6.0 (including)17.6.3 (excluding)
GitlabGitlab17.7.0 (including)17.7.1 (excluding)
GitlabUbuntuesm-apps/xenial*

Potential Mitigations

References