Where
-Infinity
0
Severity
6.5
EPSS
0.01%
Code Injection
AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N

An issue has been discovered in the GitLab Duo with Amazon Q affecting all versions from 17.8 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. A specifically crafted issue could manipulate AI-assisted development features to potentially expose sensitive project data to unauthorized users.

Remedy

Upgrade to versions 17.8.6, 17.9.3, 17.10.1 or above.
First published (updated )
EOL
May 15, 2025
Support Ends
Mar 20, 2025

End of life: 5/15/2025, End of support: 3/20/2025, Latest version: 17.9.8

First published (updated )
Severity
8.7
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

An issue has been discovered in the gitlab-web-ide-vscode-fork component distributed over CDN affecting all versions prior to 1.89.1-1.0.0-dev-20241118094343and used by all versions of GitLab CE/EE starting from 15.11 prior to 17.3 and which also temporarily affected versions 17.4, 17.5 and 17.6, where a XSS attack was possible when loading .ipynb files in the web IDE

Remedy

Upgrade to GitLab version 17.3, 17.4, 17.5, 17.6 or later.
First published (updated )
EOL
Nov 21, 2024
Support Ends
Sep 19, 2024

End of life: 11/21/2024, End of support: 9/19/2024, Latest version: 17.3.7

First published (updated )
EOL
Nov 21, 2024
Support Ends
Sep 19, 2024

End of life: 11/21/2024, End of support: 9/19/2024, Latest version: 17.3.7

First published (updated )
EOL
Jan 16, 2025
Support Ends
Nov 21, 2024

End of life: 1/16/2025, End of support: 11/21/2024, Latest version: 17.5.5

First published (updated )
EOL
Jan 16, 2025
Support Ends
Nov 21, 2024

End of life: 1/16/2025, End of support: 11/21/2024, Latest version: 17.5.5

First published (updated )
Severity
6.5
EPSS
0.05%
AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

An issue was discovered in GitLab CE/EE affecting all versions starting from 8.16 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows deploy keys to push to an archived repository.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 17.2.9, 17.3.5, 17.4.2 or above.
First published (updated )
Severity
5.3
EPSS
0.05%
AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

An issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior to 17.4.2. It was possible for an unauthenticated attacker to determine the GitLab version number for a GitLab instance.

1 / 2
Source: MITRE

Remedy

Upgrade to version 17.2.9, 17.3.5 or 17.4.2
First published (updated )
Severity
8.2
EPSS
0.07%
SSRF
AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N

An issue has been discovered in GitLab EE affecting all versions starting from 15.10 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior to 17.4.2. Instances with Product Analytics Dashboard configured and enabled could be vulnerable to SSRF attacks.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 17.2.9, 17.3.5, 17.4.2 or above.
First published (updated )
Severity
7.3
XSS
AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 17.1 prior 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2. When adding a authorizing an application, it can be made to render as HTML under specific circumstances.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 17.4.2, 17.3.5, 17.2.9 or above.
First published (updated )
Severity
9.6
EPSS
0.07%
AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

An issue was discovered in GitLab EE affecting all versions starting from 12.5 prior to 17.2.9, starting from 17.3, prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows running pipelines on arbitrary branches.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 17.2.9, 17.3.5, 17.4.2 or above.
First published (updated )
Severity
8.8
EPSS
0.07%
AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows an attacker to trigger a pipeline as another user under certain circumstances.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 17.2.9, 17.3.5, 17.4.2 or above.
First published (updated )
Severity
9.1
AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N

An issue has been discovered in GitLab EE/CE affecting all versions starting from 8.0 before 16.4. The product did not sufficiently warn about security implications of granting merge rights to protected branches.

Remedy

Upgrade to versions 16.4 or above.
First published (updated )
EOL
Oct 17, 2024
Support Ends
Aug 15, 2024

End of life: 10/17/2024, End of support: 8/15/2024, Latest version: 17.2.9

First published (updated )
EOL
Oct 17, 2024
Support Ends
Aug 15, 2024

End of life: 10/17/2024, End of support: 8/15/2024, Latest version: 17.2.9

First published (updated )
EOL
Sep 22, 2023
Support Ends
Jul 22, 2023

End of life: 9/22/2023, End of support: 7/22/2023, Latest version: 16.1.8

First published (updated )
EOL
Sep 22, 2023
Support Ends
Jul 22, 2023

End of life: 9/22/2023, End of support: 7/22/2023, Latest version: 16.1.8

First published (updated )
EOL
Aug 22, 2023
Support Ends
Jun 22, 2023

End of life: 8/22/2023, End of support: 6/22/2023, Latest version: 16.0.10

First published (updated )
EOL
Aug 22, 2023
Support Ends
Jun 22, 2023

End of life: 8/22/2023, End of support: 6/22/2023, Latest version: 16.0.10

First published (updated )
EOL
Jan 18, 2024
Support Ends
Nov 16, 2023

End of life: 1/18/2024, End of support: 11/16/2023, Latest version: 16.5.10

First published (updated )
EOL
Jan 18, 2024
Support Ends
Nov 16, 2023

End of life: 1/18/2024, End of support: 11/16/2023, Latest version: 16.5.10

First published (updated )
EOL
Dec 21, 2023
Support Ends
Oct 22, 2023

End of life: 12/21/2023, End of support: 10/22/2023, Latest version: 16.4.7

First published (updated )
EOL
Dec 21, 2023
Support Ends
Oct 22, 2023

End of life: 12/21/2023, End of support: 10/22/2023, Latest version: 16.4.7

First published (updated )
EOL
Feb 15, 2024
Support Ends
Dec 21, 2023

End of life: 2/15/2024, End of support: 12/21/2023, Latest version: 16.6.10

First published (updated )
EOL
Feb 15, 2024
Support Ends
Dec 21, 2023

End of life: 2/15/2024, End of support: 12/21/2023, Latest version: 16.6.10

First published (updated )
EOL
Dec 19, 2024
Support Ends
Oct 17, 2024

End of life: 12/19/2024, End of support: 10/17/2024, Latest version: 17.4.6

First published (updated )
EOL
Dec 19, 2024
Support Ends
Oct 17, 2024

End of life: 12/19/2024, End of support: 10/17/2024, Latest version: 17.4.6

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203