{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-01T07:47:40.461","vulnerabilities":[{"cve":{"id":"CVE-2025-5846","sourceIdentifier":"cve@gitlab.com","published":"2025-06-26T06:15:24.030","lastModified":"2026-06-17T09:48:51.877","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions from 16.10 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users to assign unrelated compliance frameworks to projects by sending crafted GraphQL mutations that bypassed framework-specific permission checks."},{"lang":"es","value":"Se ha descubierto un problema en GitLab EE que afecta a todas las versiones desde la 16.10 hasta la 17.11.5, la 18.0 hasta la 18.0.3 y la 18.1 hasta la 18.1.1 que podría haber permitido a los usuarios autenticados asignar frameworks de cumplimiento no relacionados a los proyectos mediante el envío de mutaciones GraphQL manipuladas que eludían los controles de permisos específicos del framework."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.10","lessThan":"17.11.5","versionType":"semver","status":"affected"},{"version":"18.0","lessThan":"18.0.3","versionType":"semver","status":"affected"},{"version":"18.1","lessThan":"18.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-06-26T13:22:54.557423Z","id":"CVE-2025-5846","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"17.11.5","matchCriteriaId":"07AEA00E-F0F2-4E5A-97A5-9AD0ECB732F0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.0.0","versionEndExcluding":"18.0.3","matchCriteriaId":"912DFFB2-0D98-4506-AEB6-2AC3C2330554"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"1FA1F1D0-87EA-44A6-AFB7-267BB21A7412"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/546435","source":"cve@gitlab.com","tags":["Broken Link"]}]}}]}