GitLab Multiple Vulnerabilities
Release Date: 13 Nov 2025
RISK: Medium Risk
TYPE: Servers - Other Servers
Multiple vulnerabilities were identified in GitLab. A remote attacker could exploit some of these vulnerabilities to trigger cross-site scripting, elevation of privilege, denial of service condition, sensitive information disclosure and security restriction bypass on the targeted system.
Impact
- Denial of Service
- Security Restriction Bypass
- Information Disclosure
- Elevation of Privilege
- Cross-Site Scripting
System / Technologies affected
- GitLab Community Edition (CE) versions prior to 18.5.2, 18.4.4, 18.3.6
- GitLab Enterprise Edition (EE) versions prior to 18.5.2, 18.4.4, 18.3.6
Solutions
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
Vulnerability Identifier
- CVE-2025-2615
- CVE-2025-6171
- CVE-2025-6945
- CVE-2025-7000
- CVE-2025-7736
- CVE-2025-11224
- CVE-2025-11865
- CVE-2025-11990
- CVE-2025-12983
沒有留言:
發佈留言