CVE-2025-2246 | GitLab Community Edition/Enterprise Edition up to 18.1.4/18.2.4/18.3.0 GraphQL API authorization (Issue 524592 / Nessus ID 258046)
A vulnerability categorized as problematic has been discovered in GitLab Community Edition and Enterprise Edition up to 18.1.4/18.2.4/18.3.0. The impacted element is an unknown function of the component GraphQL API. Executing manipulation can lead to missing authorization.
This vulnerability appears as CVE-2025-2246. The attack may be performed from a remote location. There is no available exploit.
It is advisable to upgrade the affected component.