Gitlab Patches Multiple Vulnerabilities Including Resource Exhaustion & User Manipulation
ID: 1b48baf1-48c8-5af8-951c-bcbb63c342ae
STIX ID: report--1b48baf1-48c8-5af8-951c-bcbb63c342ae
Feed Name: GBHackers
Threat Score
GitLab released critical patch updates for self-managed CE/EE (17.7.1, 17.6.3, 17.5.5) addressing several security flaws—notably an access-token logging issue (CVE-2025-0194), a DoS via cyclic epics (CVE-2024-6324), unauthorized issue manipulation (CVE-2024-12431), and a SAML configuration problem (CVE-2024-13041). Administrators are urged to upgrade immediately or disable importers until patched; detailed write-ups will be posted to GitLab’s issue tracker after a 30-day embargo.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
