logo

Last Week in AppSec for 28. October 2025

ID: 830b3e48-9698-53cd-bcad-1090ba0852ea

STIX ID: report--830b3e48-9698-53cd-bcad-1090ba0852ea

Feed Name: Checkmarx Zero

Threat Score
70/100

Date Published: 2025-10-28

Date Updated: 2026-04-27

Author: Darren Meyer

...
...

This Checkmarx Zero newsletter highlights multiple high- and medium-severity vulnerabilities: seven CVEs in GitLab (including a CVSS 8.5 Runner API improper access control enabling runner hijack and several DoS and authorization issues) requiring upgrades to 18.x branches, and an Apache Geode management API CSRF (CVE-2025-47410, CVSSv3=8.8) requiring update to 1.15.2+. The report advises patching, using WAF/reverse-proxy limits, network access controls, and configuration mitigations to reduce exposure and provides commands and checks to determine exposure scope.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.