Bitnami package
gitlab
pkg:bitnami/gitlab
Vulnerabilities (1,154)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2025-4278 | Hig | 8.7 | >= 18.0.0, < 18.0.2 | 18.0.2 | Jun 12, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions starting with 18.0 before 18.0.2. Under certain conditions html injection in new search page could lead to account takeover. | |
| CVE-2025-2254 | Hig | 8.7 | >= 17.9.0, < 18.0.2 | 18.0.2 | Jun 12, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Improper output encoding in the snipper viewer functionality lead to Cross-Site scripting attacks. | |
| CVE-2025-1516 | Med | 6.5 | >= 8.7.0, < 18.0.2 | 18.0.2 | Jun 12, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 8.7 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Improper input validation in Tokens Names could be used to trigger a denial of service. | |
| CVE-2025-1478 | Med | 6.5 | >= 8.13.0, < 18.0.2 | 18.0.2 | Jun 12, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 8.13 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of input validation in Board Names could be used to trigger a denial of service. | |
| CVE-2025-1763 | Hig | 8.7 | >= 16.6.0, < 17.11.1 | 17.11.1 | May 30, 2025 | An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass in a user's browser under specific conditions, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1. | |
| CVE-2024-9163 | Low | 3.5 | >= 12.1.0, < 17.11.3 | 17.11.3 | May 23, 2025 | A business logic error in GitLab CE/EE affecting all versions starting from 12.1 prior to 17.10.7, 17.11 prior to 17.11.3 and 18.0 prior to 18.0.1 where an attacker can cause a branch name confusion in confidential MRs. | |
| CVE-2024-7803 | Med | 6.5 | >= 11.6.0, < 17.11.3 | 17.11.3 | May 23, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A Discord webhook integration may cause DoS. | |
| CVE-2025-0993 | Hig | 7.5 | < 17.11.3 | 17.11.3 | May 22, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. This could allow an authenticated attacker to cause a denial of service condition by exhausting server resources. | |
| CVE-2025-0679 | Med | 4.3 | >= 17.1.0, < 17.11.3 | 17.11.3 | May 22, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 17.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Under certain conditions un-authorised users can view full email addresses that should be partially obscured. | |
| CVE-2025-0605 | Med | 4.6 | >= 16.8.0, < 17.11.3 | 17.11.3 | May 22, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group access controls could allow certain users to bypass two-factor authentication requirements. | |
| CVE-2024-12093 | Med | 6.8 | >= 11.1.0, < 17.11.3 | 17.11.3 | May 22, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Improper XPath validation allows modified SAML response to bypass 2FA requirement under specialized conditions. | |
| CVE-2025-4979 | Med | 4.9 | < 17.11.3 | 17.11.3 | May 22, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. An attacker may be able to reveal masked or hidden CI variables (that they did not author) in the WebUI, by simply creating their own variable and obs | |
| CVE-2025-3111 | Med | 6.5 | >= 10.2.0, < 17.11.3 | 17.11.3 | May 22, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 10.2 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of input validation in the Kubernetes integration could allow an authenticated user to cause denial of service.. | |
| CVE-2025-2853 | Med | 6.5 | < 17.11.3 | 17.11.3 | May 22, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of proper validation in GitLab could allow an authenticated user to cause a denial of service condition. | |
| CVE-2025-1110 | Low | 2.7 | >= 18.0.0, < 18.0.1 | 18.0.1 | May 22, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 18.0 before 18.0.1. In certain circumstances, a user with limited permissions could access Job Data via a crafted GraphQL query. | |
| CVE-2025-1278 | Med | 5.3 | >= 12.0.0, < 17.11.2 | 17.11.2 | May 9, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 12.0 before 17.9.8, 17.10 before 17.10.6, and 17.11 before 17.11.2. Under certain conditions users could bypass IP access restrictions and view sensitive information. | |
| CVE-2025-0549 | Med | 6.8 | >= 17.3.0, < 17.11.2 | 17.11.2 | May 9, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.3 prior to 17.9.8, from 17.10 prior to 17.10.6, and from 17.11 prior to 17.11.2. A security vulnerability allows attackers to bypass Device OAuth flow protections, enabling authorization form sub | |
| CVE-2024-8973 | Med | 6.5 | >= 17.1.0, < 17.11.2 | 17.11.2 | May 9, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.9.8, from 17.10 prior to 17.10.6, and from 17.11 prior to 17.11.2. It was possible to cause a DoS condition via GitHub import requests using a malicious crafted payload. | |
| CVE-2025-1908 | Hig | 7.7 | >= 16.6.0, < 17.11.1 | 17.11.1 | Apr 24, 2025 | An issue has been discovered in GitLab EE/CE that could allow an attacker to track users' browsing activities, potentially leading to full account take-over, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1. | |
| CVE-2025-0639 | Med | 6.5 | >= 16.7.0, < 17.11.1 | 17.11.1 | Apr 24, 2025 | An issue has been discovered affecting service availability via issue preview in GitLab CE/EE affecting all versions from 16.7 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1. |
- affected >= 18.0.0, < 18.0.2fixed 18.0.2
An issue has been discovered in GitLab CE/EE affecting all versions starting with 18.0 before 18.0.2. Under certain conditions html injection in new search page could lead to account takeover.
- affected >= 17.9.0, < 18.0.2fixed 18.0.2
An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Improper output encoding in the snipper viewer functionality lead to Cross-Site scripting attacks.
- affected >= 8.7.0, < 18.0.2fixed 18.0.2
An issue has been discovered in GitLab CE/EE affecting all versions from 8.7 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Improper input validation in Tokens Names could be used to trigger a denial of service.
- affected >= 8.13.0, < 18.0.2fixed 18.0.2
An issue has been discovered in GitLab CE/EE affecting all versions from 8.13 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of input validation in Board Names could be used to trigger a denial of service.
- affected >= 16.6.0, < 17.11.1fixed 17.11.1
An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass in a user's browser under specific conditions, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.
- affected >= 12.1.0, < 17.11.3fixed 17.11.3
A business logic error in GitLab CE/EE affecting all versions starting from 12.1 prior to 17.10.7, 17.11 prior to 17.11.3 and 18.0 prior to 18.0.1 where an attacker can cause a branch name confusion in confidential MRs.
- affected >= 11.6.0, < 17.11.3fixed 17.11.3
An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A Discord webhook integration may cause DoS.
- affected < 17.11.3fixed 17.11.3
An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. This could allow an authenticated attacker to cause a denial of service condition by exhausting server resources.
- affected >= 17.1.0, < 17.11.3fixed 17.11.3
An issue has been discovered in GitLab CE/EE affecting all versions from 17.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Under certain conditions un-authorised users can view full email addresses that should be partially obscured.
- affected >= 16.8.0, < 17.11.3fixed 17.11.3
An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group access controls could allow certain users to bypass two-factor authentication requirements.
- affected >= 11.1.0, < 17.11.3fixed 17.11.3
An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Improper XPath validation allows modified SAML response to bypass 2FA requirement under specialized conditions.
- affected < 17.11.3fixed 17.11.3
An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. An attacker may be able to reveal masked or hidden CI variables (that they did not author) in the WebUI, by simply creating their own variable and obs
- affected >= 10.2.0, < 17.11.3fixed 17.11.3
An issue has been discovered in GitLab CE/EE affecting all versions from 10.2 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of input validation in the Kubernetes integration could allow an authenticated user to cause denial of service..
- affected < 17.11.3fixed 17.11.3
An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of proper validation in GitLab could allow an authenticated user to cause a denial of service condition.
- affected >= 18.0.0, < 18.0.1fixed 18.0.1
An issue has been discovered in GitLab CE/EE affecting all versions from 18.0 before 18.0.1. In certain circumstances, a user with limited permissions could access Job Data via a crafted GraphQL query.
- affected >= 12.0.0, < 17.11.2fixed 17.11.2
An issue has been discovered in GitLab CE/EE affecting all versions from 12.0 before 17.9.8, 17.10 before 17.10.6, and 17.11 before 17.11.2. Under certain conditions users could bypass IP access restrictions and view sensitive information.
- affected >= 17.3.0, < 17.11.2fixed 17.11.2
An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.3 prior to 17.9.8, from 17.10 prior to 17.10.6, and from 17.11 prior to 17.11.2. A security vulnerability allows attackers to bypass Device OAuth flow protections, enabling authorization form sub
- affected >= 17.1.0, < 17.11.2fixed 17.11.2
An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.9.8, from 17.10 prior to 17.10.6, and from 17.11 prior to 17.11.2. It was possible to cause a DoS condition via GitHub import requests using a malicious crafted payload.
- affected >= 16.6.0, < 17.11.1fixed 17.11.1
An issue has been discovered in GitLab EE/CE that could allow an attacker to track users' browsing activities, potentially leading to full account take-over, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.
- affected >= 16.7.0, < 17.11.1fixed 17.11.1
An issue has been discovered affecting service availability via issue preview in GitLab CE/EE affecting all versions from 16.7 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.
Page 16 of 58