GitLab Product Security Update Advisory
ID: 5e6aac54-f468-5e6c-85eb-1dbebd73c179
STIX ID: report--5e6aac54-f468-5e6c-85eb-1dbebd73c179
Feed Name: ASEC
**Executive summary:** GitLab released critical patch updates (notably 17.1.7, 17.2.5, and 17.3.2) addressing multiple CVEs across CE/EE that could allow guest source-code access, modification of DAST checks, privilege escalation, command injection to a connected Cube server, internal request abuse via a Maven proxy, variable overwrite bypass in CI/CD templates, an OAuth open-redirect enabling account takeover in some cases, denial-of-service via crafted POST requests, and theft of session tokens via CI_JOB_TOKEN; administrators should upgrade affected versions immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
