First published: Mon Mar 03 2025(Updated: )
A Cross Site Scripting (XSS) vulnerability in GitLab-EE affecting all versions from 16.6 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows an attacker to bypass security controls and execute arbitrary scripts in a users browser under specific conditions.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=16.6<17.7.6>=17.8<17.8.4>=17.9<17.9.1 | |
>=16.6.0<17.7.6 | ||
>=17.8.0<17.8.4 | ||
=17.9.0 |
Upgrade to versions 17.7.6, 17.8.4, 17.9.1 or above.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0555 is classified as a high severity vulnerability due to its potential for executing arbitrary scripts in a user's browser.
To fix CVE-2025-0555, upgrade GitLab-EE to version 17.7.6 or later, 17.8.4 or later, or 17.9.1 or later.
CVE-2025-0555 affects GitLab-EE versions from 16.6 to 17.7.6, 17.8 to 17.8.4, and 17.9 to 17.9.1.
CVE-2025-0555 allows attackers to perform Cross Site Scripting (XSS) attacks, enabling them to execute arbitrary scripts in users' browsers.
CVE-2025-0555 was identified as a vulnerability affecting GitLab-EE, with patches released in late 2023.