In GitLab Enterprise Edition versions before 16.8.6 as well as versions starting from 16.9 before 16.9.4, and from 16.10 before 16.10.2 a medium vulnerability CVE-2023-6678 was detected. It allows attackers to crash a system by putting harmful stuff in a junit test report file. For more information, visit https://avd.aquasec.com/nvd/2023/cve-2023-6678.
Read more Developer ToolsIn GitLab CE/EE all versions starting from 16.7 to 16.8.6, from 16.9 before 16.9.4, and from 16.10 before 16.10.2 a high severity vulnerability CVE-2024-2279 was detected. Due to this vulnerability, attackers could trick the system into executing harmful actions on behalf of other users without their knowledge through a method called stored XSS (cross-site scripting). For more information, visit https://avd.aquasec.com/nvd/2024/cve-2024-2279.
Read more Developer ToolsIn OpenShift Virtualization a medium security vulnerability CVE-2024-31419 was detected. This vulnerability allows attackers to disclose limited host metrics to any guest without administrator consent. The issue is resolved in version Container-native Virtualization 4.15.1. For more information, visit https://avd.aquasec.com/nvd/2024/cve-2024-31419.
Read more Developer ToolsArgo CD users, a critical security flaw in specific versions demands immediate action to prevent unauthorized access. This vulnerability, tied to authentication mechanisms, could allow attackers to bypass login credentials. It’s found in certain session validation configurations, posing a significant risk of unauthorized changes or data access. Review your Argo CD version against official documentation to ensure you’re not vulnerable. Upgrading to the latest version is advised for enhanced security.
Read more Developer ToolsIn GitLab CE/EE versions from 6.3 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 a medium severity vulnerability CVE-2025-14157 was detected. This vulnerability allows authenticated users to trigger a denial-of-service condition by sending crafted API requests containing excessively large content parameters, leading to uncontrolled resource consumption. To address this issue, users should upgrade GitLab CE/EE to versions 18.6.2, 18.5.4 or 18.4.6. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-14157.
Read more Developer ToolsIn GitLab CE/EE versions 15.6 through 18.4.5, 18.5 through 18.5.3, and 18.6 through 18.6.1 a low severity vulnerability CVE-2025-12734 was detected. This vulnerability allows authenticated users to leak sensitive information by exploiting improper encoding or escaping in specially crafted merge request titles. To address this issue, users should upgrade GitLab CE/EE to versions 18.4.6, 18.5.4 or 18.6.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-12734.
Read more Developer ToolsIn GitLab CE/EE versions 18.4 prior to 18.4.6, 18.5 prior to 18.5.4, and 18.6 prior to 18.6.2 a high severity vulnerability CVE-2025-12716 was detected. This vulnerability allows authenticated users to perform unauthorized actions on behalf of other users by creating wiki pages containing malicious content due to improper neutralization of input during web page generation (XSS). To address this issue, users should upgrade GitLab CE/EE to versions 18.4.6, 18.5.4 or 18.6.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-12716.
Read more Developer ToolsIn GitLab CE/EE versions 11.10 through 18.4.5, 18.5 through 18.5.3, and 18.6 through 18.6.1 a high severity vulnerability CVE-2025-12562 was detected. This vulnerability allows unauthenticated users to cause a denial-of-service condition by sending crafted GraphQL queries that bypass query complexity limits, leading to uncontrolled resource consumption. To address this issue, users should upgrade GitLab CE/EE to versions 18.4.6, 18.5.4 or 18.6.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-12562.
Read more Developer ToolsIn GitLab CE/EE versions 17.5 through 18.4.5, 18.5 through 18.5.3, and 18.6 through 18.6.1 a medium severity vulnerability CVE-2025-13978 was detected. This vulnerability allows authenticated users to obtain the names of private projects they do not have access to via API error messages, potentially exposing sensitive project information. To address this issue, users should upgrade GitLab CE/EE to versions 18.4.6, 18.5.4 or 18.6.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-13978.
Read more Developer Tools