CVE-2025-5101

medium

Description

An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that under certain conditions could have allowed an authenticated attacker to distribute malicious code that appears harmless in the web interface by taking advantage of ambiguity between branches and tags during repository imports.

References

https://hackerone.com/reports/3124199

https://gitlab.com/gitlab-org/gitlab/-/issues/545165

Details

Source: Mitre, NVD

Published: 2025-08-27

Updated: 2025-08-27

Risk Information

CVSS v2

Base Score: 3.7

Vector: CVSS2#AV:L/AC:H/Au:M/C:N/I:C/A:N

Severity: Low

CVSS v3

Base Score: 5

Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:N/I:H/A:N

Severity: Medium