Medium severity4.3NVD Advisory· Published Jan 28, 2025· Updated Jun 17, 2026
CVE-2025-0290
CVE-2025-0290
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.0 prior to 17.5.5, from 17.6 prior to 17.6.3, and from 17.7 prior to 17.7.1. Under certain conditions, processing of CI artifacts metadata could cause background jobs to become unresponsive.
Affected products
15cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 15.0
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=15.0.0,<17.5.5
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=15.0.0,<17.5.5
- cpe:2.3:a:gitlab:gitlab:17.7.0:*:*:*:community:*:*:*
- cpe:2.3:a:gitlab:gitlab:17.7.0:*:*:*:enterprise:*:*:*
- (no CPE)range: from 15.0 prior to 17.5.5, from 17.6 prior to 17.6.3, and from 17.7 prior to 17.7.1
- Range: from 15.0 prior to 17.5.5, from 17.6 prior to 17.6.3, and from 17.7 prior to 17.7.1
- osv-coords8 versionspkg:apk/chainguard/gitlab-base-fips-17.6pkg:apk/chainguard/gitlab-cng-fips-17.6pkg:apk/chainguard/gitlab-container-registry-fips-17.6pkg:apk/chainguard/gitlab-elasticsearch-indexer-fips-17.6pkg:apk/chainguard/gitlab-logger-fips-17.6pkg:apk/chainguard/gitlab-shell-fips-17.6pkg:apk/chainguard/gitlab-toolbox-fips-17.6pkg:bitnami/gitlab
< 17.6.5-r0+ 7 more
- (no CPE)range: < 17.6.5-r0
- (no CPE)range: < 17.6.5-r0
- (no CPE)range: < 17.6.5-r0
- (no CPE)range: < 17.6.5-r0
- (no CPE)range: < 17.6.5-r0
- (no CPE)range: < 17.6.5-r0
- (no CPE)range: < 17.6.5-r0
- (no CPE)range: >= 15.0.0, < 17.6.4
Patches
Vulnerability mechanics
References
1- gitlab.com/gitlab-org/gitlab/-/issues/372134nvdBroken Link
News mentions
0No linked articles in our index yet.