- Description
- An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.4 and 18.0 before 18.0.2. A missing authorization check may have allowed compliance frameworks to be applied to projects outside the compliance framework's group.
- Source
- cve@gitlab.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 8.5
- Impact score
- 6
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
- Severity
- HIGH
- cve@gitlab.com
- CWE-862
- Hype score
- Not currently trending
CVE-2025-5121 An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.4 and 18.0 before 18.0.2. A missing authorization check may have allowed com… https://t.co/rXXvF4gqb8
@CVEnew
21 Jun 2025
227 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[CVE-2025-5121: HIGH] GitLab CE/EE versions 17.11 prior to 17.11.4 & 18.0 prior to 18.0.2 have a vulnerability allowing unauthorized application of compliance frameworks to projects, impacting cyber security.#cve,CVE-2025-5121,#cybersecurity https://t.co/9Qj9XA3RCP https://t.
@CveFindCom
20 Jun 2025
53 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🚨 GitLab opravuje závažnou zranitelnost, která umožňuje převzetí cizích účtů. Šlo o HTML injection, kdy mohl útočník vložit škodlivý script do vyhledávacího pole. Poslední aktualizace mimo jiné opravuje i řadu dalších chyb včetně zranitelnosti CVE-2
@AlefSecurity
14 Jun 2025
75 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🗞️ GitLab has patched high-severity vulnerabilities, including an HTML injection flaw (CVE-2025-4278) that allows account takeovers and a missing authentication issue (CVE-2025-5121) that enables malicious CI/CD job injections. Admins are urged to upgrade. Key takeaways:
@gossy_84
13 Jun 2025
67 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
GitLab has released security patches for versions 18.0.2, 17.11.4, and 17.10.8 to fix critical vulnerabilities, including account takeover via HTML injection (CVE-2025-4278) and malicious CI/CD job injections (CVE-2025-5121). Stay updated! 🔒 #GitLab #Se… https://t.co/vGyM6jK
@TweetThreatNews
12 Jun 2025
97 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes