- What: Multiple vulnerabilities have been identified in GitLab Community Edition (CE) and Enterprise Edition (EE).
- Impact: A remote attacker could exploit these vulnerabilities to trigger denial of service, cross-site scripting, and security restriction bypass.
- Affected: GitLab CE/EE versions prior to 17.8.1, 17.7.3, and 17.6.4.
- Patch: Apply the fixes issued by the vendor.
GitLab Multiple Vulnerabilities Release Date: 24 Jan 2025 5583 Views RISK: Medium Risk Medium Risk TYPE: Servers - Other Servers Multiple vulnerabilities were identified in GitLab. A remote attacker could exploit these vulnerabilities to trigger denial of service condition, cross-site scripting and security restriction bypass on the targeted system. Impact Denial of Service Cross-Site Scripting Security Restriction Bypass System / Technologies affected GitLab Community Edition (CE) versions prior to 17.8.1, 17.7.3 and 17.6.4 GitLab Enterprise Edition (EE) versions prior to 17.8.1, 17.7.3 and 17.6.4 Solutions Before installation of the software, please visit the vendor web-site for more details. Apply fixes issued by the vendor: https://about.gitlab.com/releases/2025/01/22/patch-release-gitlab-17-8-1-released/ Vulnerability Identifier CVE-2024-6324 CVE-2024-11931 CVE-2025-0314 Source GitLab Related Link https://about.gitlab.com/releases/2025/01/22/patch-release-gitlab-17-8-1-released/ Related Tags Git Denial of Service Security Restriction Bypass Cross Site Scripting Share with