Missing authorization in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2025-1754
Published: June 25, 2025
Vulnerability details
The vulnerability allows a remote attacker to upload arbitrary files to the system.
The vulnerability exists due to missing authorization checks in the API. A remote non-authenticated attacker can upload arbitrary files to public projects by sending crafted API requests and consume all available storage, leading to a denial of service condition.
Affected software
Gitlab Community Edition
How to mitigate CVE-2025-1754
Gitlab Community Edition - addressed in versions 17.11.5, 18.0.3, 18.1.1