CyberzSOC

Publication detail
← Back to advisories & guidance

2025-020: High Severity Vulnerabilities in Gitlab Products ↗ source

June 12, 2025 CERT-EU Advisory

Summary

On 11 June 2025, Gitlab released security updates for their products addressing multiple vulnerabilities in Gitlab Community Edition (CE) and Enterprise Edition (EE) [1]. It is recommended updating affected Gitlab installations as soon as possible. The vulnerability CVE-2025-4278, with a CVSS score of 8.7, is an issue that, under certain conditions, could have allowed a successful attacker to achieve account takeover by injecting The vulnerability CVE-2025-2254, with a CVSS score of 8.7, is a cross-site scripting (XSS) issue that, under certain conditions, could have allowed a successful attacker to act in the context of a legitimate user by injecting a malicious script into the snippet viewer. The vulnerability CVE-2025-5121, with a CVSS score of 8.5, is a missing authorisation vulnerability that, under certain conditions, could have allowed a successful attacker with authenticated access to a GitLab instance with a GitLab Ultimate license applied (paid customer or trial) to inject a malicious CI/CD job into all future CI/CD pipelines of any project. The vulnerability CVE-2025-0673, with a CVSS score of 7.5, is an issue that could have allowed a successful attacker to deny access to legitimate users of the targeted system by triggering an infinite redirect loop causing memory exhaustion on the server. Gitlab also fixes 5 medium and 1 low severity vulnerabilities.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2025-2254 8.7 High GitLab GitLab An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Improper …
CVE-2025-4278 8.7 High GitLab GitLab An issue has been discovered in GitLab CE/EE affecting all versions starting with 18.0 before 18.0.2. Under certain conditions html injection in new …
CVE-2025-5121 8.5 High GitLab GitLab An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.4 and 18.0 before 18.0.2. A missing authorization check m…
CVE-2025-0673 7.5 High GitLab GitLab An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2, allow an …

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.