First published: Thu Apr 24 2025(Updated: )
An issue has been discovered in GitLab EE/CE that could allow an attacker to track users' browsing activities, potentially leading to full account take-over, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >16.6<17.9.7>17.10<17.10.5>17.11<17.11.1 |
Upgrade to versions 17.9.7, 17.10.5, 17.11.1 or above.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-1908 has been classified as a high-severity vulnerability that can lead to account take-over.
To fix CVE-2025-1908, upgrade GitLab EE/CE to version 17.9.7 or later, 17.10.5 or later, or 17.11.1 or later.
CVE-2025-1908 affects GitLab EE/CE versions from 16.6 before 17.9.7, from 17.10 before 17.10.5, and from 17.11 before 17.11.1.
Yes, CVE-2025-1908 could allow attackers to track users' browsing activities, compromising user privacy.
CVE-2025-1908 is not present in GitLab releases after version 17.9.7, 17.10.5, and 17.11.1.