First published: Fri Feb 07 2025(Updated: )
A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions starting from 7.14.1 prior to 17.3.7, 17.4 prior to 17.4.4, and 17.5 prior to 17.5.2. A denial of service could occur upon importing maliciously crafted content using the Fogbugz importer.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab Community Edition | >=7.14.1<17.3.7>=17.4<17.4.4>=17.5<17.5.2 |
Upgrade to versions 17.5.2, 17.4.4, 17.3.7 or above.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-1072 is classified as a Denial of Service (DoS) vulnerability.
To fix CVE-2025-1072, upgrade to GitLab version 17.3.7 or later, 17.4.4 or later, or 17.5.2 or later.
GitLab versions from 7.14.1 to 17.3.6, 17.4 to 17.4.3, and 17.5 to 17.5.1 are affected by CVE-2025-1072.
CVE-2025-1072 is a Denial of Service (DoS) vulnerability related to importing malicious content.
Yes, CVE-2025-1072 can be exploited if a user imports maliciously crafted content using the Fogbugz importer.