In GitLab CE/EE versions 8.3 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 a medium severity vulnerability CVE-2025-1212 was detected. This vulnerability allows attackers to send crafted requests to a backend server to reveal sensitive information. To address this issue, users should upgrade GitLab CE/EE to versions 17.8.2, 17.7.4, 17.6.5 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-1212.
Read more Developer ToolsIn GitLab EE versions starting from 16.0 prior to 17.6.5, starting from 17.7 prior to 17.7.4, and starting from 17.8 prior to 17.8.2 a medium severity vulnerability CVE-2024-3303 was detected. This vulnerability allows attackers to exfiltrate the contents of a private issue using prompt injection. To address this issue, users should upgrade GitLab EE to versions 17.8.2, 17.7.4, 17.6.5 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-3303.
Read more Developer ToolsIn GitLab CE/EE versions starting from 16.4 prior to 17.5.0 a critical severity vulnerability CVE-2024-7102 was detected. This vulnerability allows attackers to trigger a pipeline as another user under certain circumstances. Currently, there is no fix version for that issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-7102.
Read more Developer ToolsIn GitLab EE versions 15.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 a medium severity vulnerability CVE-2024-9870 was detected. This vulnerability allows attackers to send requests from the GitLab server to unintended services. To address this issue, users should upgrade GitLab EE to versions 17.8.2, 17.7.4, 17.6.5 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-9870.
Read more Developer ToolsIn GitLab CE/EE versions 14.1 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 a medium severity vulnerability CVE-2024-12379 was detected. This vulnerability allows attackers to impact the availability of GitLab via unbounded symbol creation using the scopes parameter in a Personal Access Token. To address this issue, users should upgrade GitLab CE/EE to versions 17.8.2, 17.7.4, 17.6.5 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-12379.
Read more Developer ToolsIn GitLab CE/EE versions 13.3 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 a high severity vulnerability CVE-2025-0376 was detected. This vulnerability allows attackers to execute unauthorized actions via a change page through a stored Cross-Site Scripting (XSS) attack. To address this issue, users should upgrade GitLab CE/EE to versions 17.8.2, 17.7.4, 17.6.5 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-0376.
Read more Developer ToolsIn GitLab CE/EE versions 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 a medium severity vulnerability CVE-2025-0516 was detected. This vulnerability allows users with limited permissions to perform unauthorized actions on critical project data due to improper authorization. To address this issue, users should upgrade GitLab CE/EE to versions 17.8.2, 17.7.4, 17.6.5 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-0516.
Read more Developer ToolsIn GitLab CE/EE versions from 17.1 prior to 17.6.0 a medium severity vulnerability CVE-2024-8266 was detected. This vulnerability allows attackers with a maintainer role to trigger a pipeline as the project owner under certain circumstances. To address this issue, users should upgrade to version 17.6.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-8266.
Read more Developer ToolsIn Node.js versions 21.7.3 a high severity vulnerability CVE-2025-23089 was detected. This vulnerability informs users that they are using End-of-Life (EOL) versions of Node.js, which no longer receive updates or security patches, potentially exposing systems to security risks due to unaddressed vulnerabilities or dependencies. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2025/cve-2025-23089.
Read more Application Development