GitLab 17.5.4 Community Edition

CPE Details

GitLab 17.5.4 Community Edition
17.5.4
2024-12-16
17h40 +00:00
2024-12-16
17h40 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:gitlab:gitlab:17.5.4:*:*:*:community:*:*:*

Informations

Vendor

gitlab

Product

gitlab

Version

17.5.4

Software Edition

community

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2025-0605 2025-05-22 14h31 +00:00 An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group access controls could allow certain users to bypass two-factor authentication requirements.
4.6
Medium
CVE-2025-0679 2025-05-22 14h31 +00:00 An issue has been discovered in GitLab CE/EE affecting all versions from 17.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Under certain conditions un-authorised users can view full email addresses that should be partially obscured.
4.3
Medium
CVE-2025-0993 2025-05-22 14h31 +00:00 An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. This could allow an authenticated attacker to cause a denial of service condition by exhausting server resources.
7.5
High
CVE-2025-2853 2025-05-22 13h30 +00:00 An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of proper validation in GitLab could allow an authenticated user to cause a denial of service condition.
6.5
Medium
CVE-2025-3111 2025-05-22 13h30 +00:00 An issue has been discovered in GitLab CE/EE affecting all versions from 10.2 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of input validation in the Kubernetes integration could allow an authenticated user to cause denial of service..
6.5
Medium
CVE-2025-0475 2025-03-03 10h30 +00:00 An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1. A proxy feature could potentially allow unintended content rendering leading to XSS under specific circumstances.
8.7
High