An issue has been discovered in GitLab EE affecting all versions from 13.3 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that could have allowed authenticated project owners to bypass group-level forking restrictions by manipulating API requests.
                
            References
                    | Link | Resource | 
|---|---|
| https://gitlab.com/gitlab-org/gitlab/-/issues/534636 | Broken Link | 
| https://hackerone.com/reports/3079956 | Permissions Required | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    25 Jul 2025, 16:40
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | |
| First Time | Gitlab Gitlab gitlab | |
| References | () https://gitlab.com/gitlab-org/gitlab/-/issues/534636 - Broken Link | |
| References | () https://hackerone.com/reports/3079956 - Permissions Required | |
| Summary | 
 | 
10 Jul 2025, 09:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-07-10 09:15
Updated : 2025-07-25 16:40
NVD link : CVE-2025-3396
Mitre link : CVE-2025-3396
CVE.ORG link : CVE-2025-3396
JSON object : View
Products Affected
                gitlab
- gitlab
CWE
                
                    
                        
                        CWE-863
                        
            Incorrect Authorization
