First published: Wed Feb 12 2025(Updated: )
An XSS vulnerability exists in GitLab CE/EE affecting all versions from 13.3 prior to 17.6.5, 17.7 prior to 17.7.4 and 17.8 prior to 17.8.2 that allows an attacker to execute unauthorized actions via a change page.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab Community Edition | >=13.3<17.6.5>=17.7<17.7.4>=17.8<17.8.2 |
Upgrade to versions 17.6.5, 17.7.4, 17.8.2 or above.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0376 has a high severity rating due to its potential for allowing unauthorized actions through XSS attacks.
To fix CVE-2025-0376, upgrade GitLab CE/EE to version 17.6.5 or later, 17.7.4 or later, or 17.8.2 or later.
CVE-2025-0376 affects all versions of GitLab CE/EE from 13.3 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2.
CVE-2025-0376 is an XSS (Cross-Site Scripting) vulnerability.
Attackers can execute unauthorized actions via a change page due to the XSS vulnerability in CVE-2025-0376.