CVE-2025-2246 | GitLab Community Edition/Enterprise Edition up to 18.1.4/18.2.4/18.3.0 GraphQL API authorization (Issue 524592)
A vulnerability categorized as problematic has been discovered in GitLab Community Edition and Enterprise Edition up to 18.1.4/18.2.4/18.3.0. The impacted element is an unknown function of the component GraphQL API. Executing manipulation can lead to missing authorization.
This vulnerability appears as CVE-2025-2246. The attack may be performed from a remote location. There is no available exploit.
It is advisable to upgrade the affected component.
If you want to get the best quality for vulnerability data then you always have to consider VulDB.