- Description
- An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.6.4, 17.7 before 17.7.3, and 17.8 before 17.8.1. Improper rendering of certain file types lead to cross-site scripting.
- Source
- cve@gitlab.com
- NVD status
- Analyzed
- Products
- gitlab
CVSS 3.1
- Type
- Primary
- Base score
- 6.1
- Impact score
- 2.7
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Severity
- MEDIUM
- cve@gitlab.com
- CWE-79
- Hype score
- Not currently trending
به تازگی برای GITLAB سه آسیب پذیری با کدهای شناسایی CVE-2025-0314 از نوع xss و CVE-2024-11931 و CVE-2024-6324 که از نوع DOS می باشد ، منتشر شده است. برای پیشگیری و مقابله با این تهدیدات ، به نسخه 17.6.4 یا 17.7.3 به روز رسانی نمایید. https://t.co/Poz3aKY03t https://t.co/wjUdarPR
@AmirHossein_sec
30 Jan 2025
34 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-0314 (CVSS:8.7, HIGH) is Awaiting Analysis. An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.6.4, 17.7 before 17.7.3, and 17...https://t.co/0vUv1lJ8ev #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre
@cracbot
29 Jan 2025
14 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
GitLab has released critical updates for versions 17.8.1, 17.7.3, and 17.6.4 to fix multiple vulnerabilities, including a severe XSS flaw (CVE-2025-0314). Update now! 🔒🛡️ #GitLab #XSS #USA link: https://t.co/BY1QZYae28 https://t.co/2jl9zWTxBr
@TweetThreatNews
24 Jan 2025
36 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
【リンク集:1月23日〜24日のセキュリティ関連ニュース/記事】 <脆弱性> ・シスコ、Meeting Managementにおける重大な権限昇格の脆弱性を修正(CVE -2025-20156、CVSS 9.9) https://t.co/porqgYKPGk ・CVE-2025-0314:GitLabがXSS脆弱性のパッチをリリース https://t.co/putaDwxPc5… https://t.co/PTvD8feaBr
@MachinaRecord
24 Jan 2025
87 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
[CVE-2025-0314: HIGH] URGENT: GitLab CE/EE versions 17.2-17.6.4, 17.7-17.7.3, & 17.8-17.8.1 found vulnerable to cross-site scripting due to file rendering. Update to stay secure. #cybersecurity#cybersecurity,#vulnerability https://t.co/PRdzXGcsZT https://t.co/wQHK4O3mvJ
@CveFindCom
24 Jan 2025
75 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-0314 impacts GitLab #Gitlab #CVE-2025-0314 https://t.co/FKmRE1xpAo
@pravin_karthik
23 Jan 2025
44 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-0314: GitLab Releases Patch for XSS Exploit GitLab security update: Addressing multiple vulnerabilities, including the high severity cross-site scripting flaw (CVE-2025-0314). Stay protected! https://t.co/cANvI2kAHX
@the_yellow_fall
23 Jan 2025
30 Impressions
1 Retweet
2 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6E818ED4-C5E6-4305-A26D-988D6246A6EB",
"versionEndExcluding": "17.6.4",
"versionStartIncluding": "17.2.0"
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5C1A5D6E-9FA4-44C1-B1B4-DABD78AC9DE5",
"versionEndExcluding": "17.6.4",
"versionStartIncluding": "17.2.0"
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F58DBE0B-3F1A-4F44-A908-78C245D15151",
"versionEndExcluding": "17.7.3",
"versionStartIncluding": "17.7.0"
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BE3A08B9-AB93-4384-AC6F-479770F8F179",
"versionEndExcluding": "17.7.3",
"versionStartIncluding": "17.7.0"
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:17.8.0:*:*:*:community:*:*:*",
"vulnerable": true,
"matchCriteriaId": "28392021-9008-4FE2-9425-C0F0DCF10119"
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:17.8.0:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "51714D27-77B8-422D-B946-2277FB0DA2E7"
}
],
"operator": "OR"
}
]
}
]