GitLab Multiple Vulnerabilities
Release Date: 22 May 2025
RISK: Medium Risk
TYPE: Servers - Other Servers
Multiple vulnerabilities were identified in GitLab. A remote attacker could exploit some of these vulnerabilities to trigger sensitive information disclosure, denial of service condition and security restriction bypass on the targeted system.
Impact
- Denial of Service
- Security Restriction Bypass
- Information Disclosure
System / Technologies affected
- GitLab Community Edition (CE) versions prior to 18.0.1, 17.11.3, and 17.10.7
- GitLab Enterprise Edition (EE) versions prior to 18.0.1, 17.11.3, and 17.10.7
Solutions
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
Vulnerability Identifier
- CVE-2024-7803
- CVE-2024-9163
- CVE-2024-12093
- CVE-2025-0605
- CVE-2025-0679
- CVE-2025-0993
- CVE-2025-1110
- CVE-2025-2853
- CVE-2025-3111
- CVE-2025-4979
沒有留言:
發佈留言