logo

Gitlab Patches Multiple Vulnerabilities Including Resource Exhaustion & User Manipulation

ID: 1b48baf1-48c8-5af8-951c-bcbb63c342ae

STIX ID: report--1b48baf1-48c8-5af8-951c-bcbb63c342ae

Feed Name: GBHackers

Threat Score
50/100

Date Published: 2025-01-09

Date Updated: 2026-04-22

Author: Divya

...
...

GitLab released critical patch updates for self-managed CE/EE (17.7.1, 17.6.3, 17.5.5) addressing several security flaws—notably an access-token logging issue (CVE-2025-0194), a DoS via cyclic epics (CVE-2024-6324), unauthorized issue manipulation (CVE-2024-12431), and a SAML configuration problem (CVE-2024-13041). Administrators are urged to upgrade immediately or disable importers until patched; detailed write-ups will be posted to GitLab’s issue tracker after a 30-day embargo.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.