In GitLab EE versions starting from 16.0 prior to 17.6.5, starting from 17.7 prior to 17.7.4, and starting from 17.8 prior to 17.8.2 a medium severity vulnerability CVE-2024-3303 was detected. This vulnerability allows attackers to exfiltrate the contents of a private issue using prompt injection. To address this issue, users should upgrade GitLab EE to versions 17.8.2, 17.7.4, 17.6.5 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-3303.
Read more Developer ToolsIn GitLab CE/EE versions starting from 16.4 prior to 17.5.0 a critical severity vulnerability CVE-2024-7102 was detected. This vulnerability allows attackers to trigger a pipeline as another user under certain circumstances. Currently, there is no fix version for that issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-7102.
Read more Developer ToolsIn GitLab CE/EE versions from 17.1 prior to 17.6.0 a medium severity vulnerability CVE-2024-8266 was detected. This vulnerability allows attackers with a maintainer role to trigger a pipeline as the project owner under certain circumstances. To address this issue, users should upgrade to version 17.6.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-8266.
Read more Developer ToolsIn GitLab EE versions 15.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 a medium severity vulnerability CVE-2024-9870 was detected. This vulnerability allows attackers to send requests from the GitLab server to unintended services. To address this issue, users should upgrade GitLab EE to versions 17.8.2, 17.7.4, 17.6.5 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-9870.
Read more Developer ToolsIn GitLab CE/EE versions 14.1 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 a medium severity vulnerability CVE-2024-12379 was detected. This vulnerability allows attackers to impact the availability of GitLab via unbounded symbol creation using the scopes parameter in a Personal Access Token. To address this issue, users should upgrade GitLab CE/EE to versions 17.8.2, 17.7.4, 17.6.5 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-12379.
Read more Developer ToolsIn GitLab CE/EE versions 13.3 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 a high severity vulnerability CVE-2025-0376 was detected. This vulnerability allows attackers to execute unauthorized actions via a change page through a stored Cross-Site Scripting (XSS) attack. To address this issue, users should upgrade GitLab CE/EE to versions 17.8.2, 17.7.4, 17.6.5 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-0376.
Read more Developer ToolsIn GitLab CE/EE versions 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 a medium severity vulnerability CVE-2025-0516 was detected. This vulnerability allows users with limited permissions to perform unauthorized actions on critical project data due to improper authorization. To address this issue, users should upgrade GitLab CE/EE to versions 17.8.2, 17.7.4, 17.6.5 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-0516.
Read more Developer ToolsIn Brizy – Page Builder plugin for WordPress versions 2.6.8 and prior a medium severity vulnerability CVE-2024-10322 was detected. This vulnerability allows authenticated attackers with Author-level access and above to exploit insufficient input sanitization and output escaping via REST API SVG file uploads, potentially resulting in stored Cross-Site Scripting (XSS) attacks that inject arbitrary web scripts, which execute whenever a user accesses the SVG file. To address this issue, users should upgrade Brizy – Page Builder plugin to version 2.6.9 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-10322.
Read more Newsflash Business and Enterprise SolutionsIn OpenShift version 4 a medium severity vulnerability CVE-2025-0750 was detected in CRI-O. This vulnerability allows an attacker with permissions to create and delete Pods to unmount arbitrary host paths due to a path traversal issue in the log management functions (UnMountPodLogs and LinkContainerLogs). Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2025/cve-2025-0750.
Read more Developer Tools