CVE-2025-11340
- EPSS 0.35%
- Veröffentlicht 09.10.2025 12:04:20
- Zuletzt bearbeitet 20.10.2025 21:00:37
GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 to 18.3.4, 18.4 to 18.4.2 that, under certain conditions, could have allowed authenticated users with read-only API tokens to perform unauthorized write operations on vulner...
CVE-2025-2934
- EPSS 0.5%
- Veröffentlicht 09.10.2025 11:33:43
- Zuletzt bearbeitet 20.10.2025 21:01:34
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 5.2 prior to 18.2.8, 18.3 prior to 18.3.4, and 18.4 prior to 18.4.2 that could have allowed an authenticated attacker to create a denial of service condition by configuring ma...
CVE-2025-8014
- EPSS 0.57%
- Veröffentlicht 27.09.2025 17:15:33
- Zuletzt bearbeitet 03.10.2025 18:23:37
Denial of Service issue in GraphQL endpoints in Gitlab EE/CE affecting all versions from 11.10 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1 allows unauthenticated users to potentially bypass query complexity limits leading to resou...
CVE-2025-11042
- EPSS 0.29%
- Veröffentlicht 26.09.2025 10:15:47
- Zuletzt bearbeitet 29.09.2025 13:11:50
An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that allows an attacker to cause uncontrolled CPU consumption, potentially leading to a Denial of Service (Do...
CVE-2025-5069
- EPSS 0.23%
- Veröffentlicht 26.09.2025 10:15:47
- Zuletzt bearbeitet 29.09.2025 13:12:20
An issue has been discovered in GitLab CE/EE affecting all versions from 17.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could have allowed an authenticated user to gain unauthorized access to confidential issues by creating a pr...
CVE-2025-10868
- EPSS 0.24%
- Veröffentlicht 26.09.2025 10:15:46
- Zuletzt bearbeitet 29.09.2025 13:11:31
An issue has been discovered in GitLab CE/EE affecting all versions from 17.4 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 where certain string conversion methods exhibit performance degradation with large inputs.
CVE-2025-9642
- EPSS 0.51%
- Veröffentlicht 26.09.2025 09:15:49
- Zuletzt bearbeitet 29.09.2025 13:10:11
An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could allow an attacker to inject malicious content that may lead to account takeover.
CVE-2025-9958
- EPSS 0.46%
- Veröffentlicht 26.09.2025 09:15:49
- Zuletzt bearbeitet 06.11.2025 18:15:45
An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that could have allowed Guest users to access sensitive information stored in virtual registry configurations.
CVE-2025-7691
- EPSS 0.35%
- Veröffentlicht 26.09.2025 09:15:48
- Zuletzt bearbeitet 29.09.2025 13:10:00
A privilege escalation issue has been discovered in GitLab EE affecting all versions from 16.6 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1 that could have allowed a developer with specific group management permissions to escalate ...
CVE-2025-10867
- EPSS 0.31%
- Veröffentlicht 26.09.2025 09:15:31
- Zuletzt bearbeitet 29.09.2025 13:09:42
An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could have allowed an authenticated user to create a denial-of-service condition by exploiting an unprotected...