First published: Mon Mar 03 2025(Updated: )
An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1. A proxy feature could potentially allow unintended content rendering leading to XSS under specific circumstances.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab Community Edition | >=15.10<17.7.6>=17.8<17.8.4>=17.9<17.9.1 |
Upgrade to versions 17.7.6, 17.8.4, 17.9.1 or above.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0475 is classified as a moderate severity vulnerability that can lead to cross-site scripting (XSS).
To fix CVE-2025-0475, upgrade GitLab CE/EE to version 17.7.6 or later, 17.8.4 or later, or 17.9.1 or later.
CVE-2025-0475 affects GitLab CE/EE versions from 15.10 up to, but not including, 17.7.6, 17.8 up to, but not including, 17.8.4, and 17.9 up to, but not including, 17.9.1.
Due to CVE-2025-0475, an attacker may exploit the proxy feature to render unintended content, which can lead to cross-site scripting (XSS) attacks.
Currently, the best mitigation for CVE-2025-0475 is to upgrade to a patched version of GitLab, as no official workarounds have been provided.