GitLab Multiple Vulnerabilities
Release Date: 15 Aug 2025
RISK: Medium Risk
TYPE: Servers - Other Servers
Multiple vulnerabilities were identified in GitLab. A remote attacker could exploit some of these vulnerabilities to trigger cross-site scripting, data manipulation, sensitive information disclosure, denial of service condition and security restriction bypass on the targeted system.
Impact
- Denial of Service
- Security Restriction Bypass
- Data Manipulation
- Cross-Site Scripting
- Information Disclosure
System / Technologies affected
- GitLab Community Edition (CE) versions prior to 18.2.2, 18.1.4 and 18.0.6
- GitLab Enterprise Edition (EE) versions prior to 18.2.2, 18.1.4 and 18.0.6
Solutions
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
Vulnerability Identifier
- CVE-2024-10219
- CVE-2024-12303
- CVE-2025-1477
- CVE-2025-2498
- CVE-2025-2614
- CVE-2025-2937
- CVE-2025-5819
- CVE-2025-6186
- CVE-2025-7734
- CVE-2025-7739
- CVE-2025-8094
- CVE-2025-8770
沒有留言:
發佈留言