VYPR

Bitnami package

gitlab

pkg:bitnami/gitlab

Vulnerabilities (1,154)

  • CVE-2025-6195MedNov 26, 2025
    affected >= 13.7.0, < 18.4.5fixed 18.4.5

    GitLab has remediated an issue in GitLab EE affecting all versions from 13.7 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have allowed an authenticated user to view information from security reports under certain configuration conditions.

  • CVE-2025-13611LowNov 26, 2025
    affected >= 13.2.0, < 18.4.5fixed 18.4.5

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.5.5 and 18.6 before 18.6.3 that could have allowed an authenticated user with access to certain logs to obtain sensitive tokens under specific conditions.

  • CVE-2025-12653MedNov 26, 2025
    affected >= 18.3.0, < 18.4.5fixed 18.4.5

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that under specific conditions could have allowed an unauthenticated user to join arbitrary organizations by changing headers on some requests

  • CVE-2025-12571HigNov 26, 2025
    affected >= 17.10.0, < 18.4.5fixed 18.4.5

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have allowed an unauthenticated user to cause a Denial of Service condition by sending specifically crafted requests containing ma

  • CVE-2025-9825MedNov 21, 2025
    affected >= 13.7.0, < 18.2.8fixed 18.2.8

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 to 18.2.8, 18.3 before 18.3.4, and 18.4 before 18.4.2 that could have allowed authenticated users without project membership to view sensitive manual CI/CD variables by querying the GraphQL API.

  • CVE-2025-12983LowNov 15, 2025
    affected >= 16.9.0, < 18.3.6fixed 18.3.6

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to cause a denial of service condition by submitting specially crafted markdown content with

  • CVE-2025-7736LowNov 15, 2025
    affected >= 17.9.0, < 18.3.6fixed 18.3.6

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.9 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to bypass access control restrictions and view GitLab Pages content intended only for projec

  • CVE-2025-7000MedNov 15, 2025
    affected >= 17.6.0, < 18.3.6fixed 18.3.6

    An issue has been discovered in GitLab CE/EE affecting all versions from 17.6 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that, under specific conditions, could have allowed unauthorized users to view confidential branch names by accessing project issues with rel

  • CVE-2025-6945LowNov 15, 2025
    affected >= 17.8.0, < 18.3.6fixed 18.3.6

    GitLab has remediated an issue in GitLab EE affecting all versions from 17.8 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to leak sensitive information from confidential issues by injecting hidden prompts into merge r

  • CVE-2025-6171MedNov 15, 2025
    affected >= 13.2.0, < 18.3.6fixed 18.3.6

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker with reporter access to view branch names and pipeline details by accessing the packages API

  • CVE-2025-2615MedNov 15, 2025
    affected >= 16.7.0, < 18.3.6fixed 18.3.6

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that could have allowed a blocked user to access sensitive information by establishing GraphQL subscriptions through WebSocket connections.

  • CVE-2025-11990LowNov 15, 2025
    affected >= 18.4.0, < 18.4.4fixed 18.4.4

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated user to gain CSRF tokens by exploiting improper input validation in repository references combined with redirect handling we

  • CVE-2025-11865MedNov 15, 2025
    affected >= 18.1.0, < 18.3.6fixed 18.3.6

    An issue has been discovered in GitLab EE affecting all versions from 18.1 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that, under certain circumstances, could have allowed an attacker to remove Duo flows of another user.

  • CVE-2025-11702HigOct 29, 2025
    affected >= 17.1.0, < 18.3.5fixed 18.3.5

    GitLab has remediated an issue in EE affecting all versions from 17.1 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker with specific permissions to hijack project runners from other projects.

  • CVE-2025-6601LowOct 27, 2025
    affected >= 18.4.0, < 18.4.3fixed 18.4.3

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.3, and 18.5 before 18.5.1 that under certain conditions could have allowed authenticated users to gain unauthorized project access by exploiting the access request approval workflow.

  • CVE-2025-11989LowOct 27, 2025
    affected >= 17.6.0, < 18.3.5fixed 18.3.5

    GitLab has remediated an issue in GitLab EE affecting all versions from 17.6.0 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker to execute unauthorized quick actions by including malicious commands in specific description

  • CVE-2025-11974MedOct 27, 2025
    affected >= 11.7.0, < 18.3.5fixed 18.3.5

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.7 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to create a denial of service condition by uploading large files to specific API endpoints

  • CVE-2025-11971MedOct 27, 2025
    affected >= 10.6.0, < 18.3.5fixed 18.3.5

    GitLab has remediated an issue in GitLab EE affecting all versions from 10.6 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker to trigger unauthorized pipeline executions by manipulating commits.

  • CVE-2025-11447HigOct 27, 2025
    affected >= 11.0.0, < 18.3.5fixed 18.3.5

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.0 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to cause a denial of service condition by sending GraphQL requests with crafted JSON paylo

  • CVE-2025-10497HigOct 27, 2025
    affected >= 17.10.0, < 18.3.5fixed 18.3.5

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to cause a denial of service condition by sending specially crafted payloads.

Page 12 of 58