CVE-2025-6769
- EPSS 0.01%
- Veröffentlicht 12.09.2025 06:15:43
- Zuletzt bearbeitet 20.09.2025 02:55:46
An issue has been discovered in GitLab CE/EE affecting all versions from 15.1 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed authenticated users to view administrator-only maintenance notes by accessing runner detai...
CVE-2025-7337
- EPSS 0.04%
- Veröffentlicht 12.09.2025 06:15:43
- Zuletzt bearbeitet 20.09.2025 02:55:16
An issue has been discovered in GitLab CE/EE affecting all versions from 7.8 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed an authenticated user with Developer-level access to cause a persistent denial of service a...
CVE-2025-1250
- EPSS 0.04%
- Veröffentlicht 12.09.2025 06:15:42
- Zuletzt bearbeitet 20.09.2025 02:56:35
An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed an authenticated user to stall background job processing by sending specially crafted comm...
CVE-2025-2256
- EPSS 0.06%
- Veröffentlicht 12.09.2025 06:15:42
- Zuletzt bearbeitet 20.09.2025 02:56:22
An issue has been discovered in GitLab CE/EE affecting all versions from 7.12 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed unauthorized users to render the GitLab instance unresponsive to legitimate users by sendi...
CVE-2025-6454
- EPSS 0.02%
- Veröffentlicht 12.09.2025 06:15:42
- Zuletzt bearbeitet 20.09.2025 02:56:00
An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed authenticated users to make unintended internal requests through proxy environments by in...
CVE-2025-10094
- EPSS 0.03%
- Veröffentlicht 12.09.2025 04:57:11
- Zuletzt bearbeitet 20.09.2025 02:56:50
An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed authenticated users to disrupt access to token listings and related administrative operati...
CVE-2025-2246
- EPSS 0.03%
- Veröffentlicht 27.08.2025 19:34:00
- Zuletzt bearbeitet 02.09.2025 17:49:38
An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could have allowed unauthenticated users to access sensitive manual CI/CD variables by querying the GraphQL API.
CVE-2025-3601
- EPSS 0.04%
- Veröffentlicht 27.08.2025 19:33:50
- Zuletzt bearbeitet 02.09.2025 17:49:04
An issue has been discovered in GitLab CE/EE affecting all versions from 8.15 before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could have could have allowed an authenticated user to cause a Denial of Service (DoS) condition by submittin...
CVE-2025-4225
- EPSS 0.06%
- Veröffentlicht 27.08.2025 19:33:45
- Zuletzt bearbeitet 02.09.2025 17:48:43
An issue has been discovered in GitLab CE/EE affecting all versions from 14.1 before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that that under certain conditions could have allowed an unauthenticated attacker to cause a denial-of-service con...
- EPSS 0.02%
- Veröffentlicht 27.08.2025 19:33:36
- Zuletzt bearbeitet 02.09.2025 17:47:34
An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that under certain conditions could have allowed an authenticated attacker to distribute malicious code that appears harmles...