In GitLab versions 17.4 to 17.8.6, 17.9 to 17.9.3 and 17.10 to 17.10.1 a high severity vulnerability CVE-2025-2242 was detected. This vulnerability allows a user who was previously an instance admin but has since been downgraded to a regular user to maintain elevated privileges over groups and projects. To address this issue, users should upgrade GitLab to versions 17.8.6, 17.9.3 or 17.10.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-2242.
Read more Developer ToolsIn Kubernetes k8s.io/kubernetes/cmd/kube-apiserver package versions 1.3.0 up to and including 1.32.3 a low severity vulnerability CVE-2024-7598 was detected. This vulnerability allows attackers to bypass network restrictions enforced by network policies during namespace deletion, as the undefined order of object deletion may result in network policies being removed before the pods they protect, creating a brief window where network policies are not enforced. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-7598.
Read more Developer ToolsIn GitLab EE versions 16.5 prior to 17.7.7, 17.8 prior to 17.8.5 and 17.9 prior to 17.9.2 a low severity vulnerability CVE-2024-7296 was detected. This vulnerability allows a user with custom permissions to approve pending membership requests beyond the maximum number of allowed users. To address this issue, users should upgrade GitLab EE to versions 17.7.7, 17.8.5 or 17.9.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-7296.
Read more Developer ToolsIn GitLab EE versions 12.3 prior to 17.7.7, 17.8 prior to 17.8.5 and 17.9 prior to 17.9.2 a medium severity vulnerability CVE-2025-1257 was detected. This vulnerability allows attackers to cause a denial of service condition by manipulating specific API inputs. To address this issue, users should upgrade GitLab EE to versions 17.7.7, 17.8.5 or 17.9.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-1257.
Read more Developer ToolsIn GitLab EE versions 12.3 before 17.7.7, 17.8 before 17.8.5 and 17.9 before 17.9.2 a medium severity vulnerability CVE-2025-1257 was detected. This vulnerability allows attackers to cause a denial of service condition by manipulating specific API inputs. To address this issue, users should upgrade GitLab EE to versions 17.7.7, 17.8.5 or 17.9.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-1257.
Read more Developer ToolsIn GitLab EE/CE versions 16.9 before 17.7.7, 17.8 before 17.8.5 and 17.9 before 17.9.2 a medium severity vulnerability CVE-2025-0652 was detected. This vulnerability allows unauthorized users to access confidential information intended for internal use only. To address this issue, users should upgrade to versions 17.7.7, 17.8.5 or 17.9.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-0652.
Read more Developer ToolsIn GitLab CE/EE versions before 17.7.7, 17.8 before 17.8.5 and 17.9 before 17.9.2 a medium severity vulnerability CVE-2024-13054 was detected. This vulnerability allows an attacker to cause a system reboot under certain conditions, leading to a denial of service. To address this issue, users should upgrade GitLab CE/EE to versions 17.7.7, 17.8.5 or 17.9.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-13054.
Read more Developer ToolsIn GitLab EE/CE versions from 11.5 before 17.7.7, 17.8 before 17.8.5 and 17.9 before 17.9.2 a medium severity vulnerability CVE-2024-12380 was detected. This vulnerability allows certain user inputs in repository mirroring settings to potentially expose sensitive authentication information. To address this issue, users should upgrade GitLab EE/CE to versions 17.7.7, 17.8.5 or 17.9.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-12380.
Read more Developer ToolsIn GitLab EE versions from 17.2 before 17.7.7, 17.8 before 17.8.5 and 17.9 before 17.9.2 a low severity vulnerability CVE-2024-8402 was detected. This vulnerability allows a Maintainer to introduce malicious code due to an input validation issue in the Google Cloud IAM integration feature. To address this issue, users should upgrade GitLab EE to versions 17.7.7, 17.8.5 or 17.9.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-8402.
Read more Developer Tools