In GitLab CE/EE versions starting from 16.4 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1 a medium severity vulnerability CVE-2024-13041 was detected. This vulnerability allows attackers to bypass user access restrictions, potentially giving unauthorized users access to internal projects or groups in GitLab. To fix this issue, users should upgrade GitLab CE/EE to versions 17.5.5, 17.6.3, 17.7.1. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-13041.
Read more Developer ToolsIn GitLab CE/EE versions starting from 15.5 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1 a medium severity vulnerability CVE-2024-12431 was detected. This vulnerability allows attackers to change the status of issues in public projects on GitLab, even if they are not authorized. To fix this issue, users should upgrade GitLab CE/EE to versions 15.5, 17.6.3, 17.7.1. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-12431.
Read more Developer ToolsIn GitLab EE versions 18.5 before 18.5.5, 18.6 before 18.6.3 and 18.7 before 18.7.1 a medium severity vulnerability CVE-2025-13781 was detected. This vulnerability allows an authenticated attacker to modify instance-wide AI feature provider settings by exploiting missing authorization checks in GraphQL mutations. To address this issue, users should upgrade GitLab EE to versions 18.5.5, 18.6.3, 18.7.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-13781.
Read more Developer ToolsIn GitLab CE/EE versions 18.6 before 18.6.3 and 18.7 before 18.7.1 a high severity vulnerability CVE-2025-13761 was detected. This vulnerability allows unauthenticated attackers to execute arbitrary code in the context of an authenticated user’s browser by exploiting improper input neutralization and convincing a user to visit a specially crafted webpage. To address this issue, users should upgrade GitLab CE/EE to versions 18.6.3, 18.7.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-13761.
Read more Developer ToolsIn GitLab CE/EE versions 15.4 before 18.5.5, 18.6 before 18.6.3 and 18.7 before 18.7.1 a medium severity vulnerability CVE-2025-11246 was detected. This vulnerability allows an authenticated user with specific permissions to remove all project runners from unrelated projects by manipulating GraphQL runner associations due to insufficient granularity of access control. To address this issue, users should upgrade GitLab CE/EE to versions 18.5.5, 18.6.3, 18.7.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-11246.
Read more Developer ToolsIn GitLab CE/EE versions from 8.3 before 18.5.5, 18.6 before 18.6.3 and 18.7 before 18.7.1 a medium severity vulnerability CVE-2025-10569 was detected. This vulnerability allows an authenticated user to trigger a denial of service condition by supplying crafted responses to external API calls, exploiting missing limits or throttling on resource allocation. To address this issue, users should upgrade GitLab CE/EE to versions 18.5.5, 18.6.3, 18.7.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-10569.
Read more Developer ToolsIn GitLab EE versions 18.4 before 18.5.5, 18.6 before 18.6.3 and 18.7 before 18.7.1 a high severity vulnerability CVE-2025-13772 was detected. This vulnerability allows an authenticated attacker to access and use AI model settings from unauthorized namespaces by manipulating namespace identifiers in API requests due to missing authorization checks. To address this issue, users should upgrade GitLab EE to versions 18.5.5, 18.6.3, 18.7.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-13772.
Read more Developer ToolsIn OpenShift versions 4 and JBoss Fuse version 7 a high severity vulnerability CVE-2024-45497 was detected. This vulnerability allows attackers to overwrite a configuration file containing sensitive credentials. By modifying this file, attackers can cause a denial of service by preventing the node from pulling new images and potentially exfiltrating sensitive secrets. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-45497.
Read more Developer ToolsIn GitLab versions before 17.6.0 a low severity vulnerability CVE-2023-5117 was detected. This vulnerability allows attackers to access files uploaded to comments on confidential issues and epics of public projects without authentication via a direct link to the uploaded file URL. To address this issue, users should upgrade to version 17.6.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2023-5117.
Read more Developer Tools