From 5626746c4a9498bc4b77bbdcf2fd2b2f15df69d2 Mon Sep 17 00:00:00 2001 From: Matthias Fechner Date: Thu, 24 Apr 2025 06:18:06 +0300 Subject: [PATCH] security/vuxml: document gitlab vulnerabilities --- security/vuxml/vuln/2025.xml | 37 ++++++++++++++++++++++++++++++++++++ 1 file changed, 37 insertions(+) diff --git a/security/vuxml/vuln/2025.xml b/security/vuxml/vuln/2025.xml index 144605472dde..5455c89cedde 100644 --- a/security/vuxml/vuln/2025.xml +++ b/security/vuxml/vuln/2025.xml @@ -1,3 +1,40 @@ + + Gitlab -- Vulnerabilities + + + gitlab-ce + gitlab-ee + 17.11.017.11.1 + 17.10.017.10.5 + 16.6.017.9.7 + + + + +

Gitlab reports:

+
+

Cross Site Scripting (XSS) in Maven Dependency Proxy through CSP directives

+

Cross Site Scripting (XSS) in Maven dependency proxy through cache headers

+

Network Error Logging (NEL) Header Injection in Maven Dependency Proxy Allows Browser Activity Monitoring

+

Denial of service (DOS) via issue preview

+

Unauthorized access to branch names when Repository assets are disabled in the project

+
+ +
+ + CVE-2025-1763 + CVE-2025-2443 + CVE-2025-1908 + CVE-2025-0639 + CVE-2024-12244 + https://about.gitlab.com/releases/2025/04/23/patch-release-gitlab-17-11-1-released/ + + + 2025-04-23 + 2025-04-24 + +
+ chromium -- multiple security fixes