
CVE-2025-1212 – Exposure of Sensitive System Information to an Unauthorized Control Sphere in GitLab
https://notcve.org/view.php?id=CVE-2025-1212
12 Feb 2025 — An information disclosure vulnerability in GitLab CE/EE affecting all versions from 8.3 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to send a crafted request to a backend server to reveal sensitive information. • https://gitlab.com/gitlab-org/gitlab/-/issues/502196 • CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere •

CVE-2025-1042 – Files or Directories Accessible to External Parties in GitLab
https://notcve.org/view.php?id=CVE-2025-1042
12 Feb 2025 — An insecure direct object reference vulnerability in GitLab EE affecting all versions from 15.7 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to view repositories in an unauthorized way. • https://gitlab.com/gitlab-org/gitlab/-/issues/50849943 • CWE-552: Files or Directories Accessible to External Parties •

CVE-2025-1072 – Allocation of Resources Without Limits or Throttling in GitLab
https://notcve.org/view.php?id=CVE-2025-1072
07 Feb 2025 — A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions starting from 7.14.1 prior to 17.3.7, 17.4 prior to 17.4.4, and 17.5 prior to 17.5.2. A denial of service could occur upon importing maliciously crafted content using the Fogbugz importer. • https://about.gitlab.com/releases/2024/11/13/patch-release-gitlab-17-5-2-released/#denial-of-service-by-importing-malicious-crafted-fogbugz-import-payload • CWE-770: Allocation of Resources Without Limits or Throttling •

CVE-2024-5528 – Incomplete Comparison with Missing Factors in GitLab
https://notcve.org/view.php?id=CVE-2024-5528
05 Feb 2025 — An issue was discovered in GitLab CE/EE affecting all versions prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows a subdomain takeover in GitLab Pages. • https://gitlab.com/gitlab-org/gitlab/-/issues/464558 • CWE-1023: Incomplete Comparison with Missing Factors •

CVE-2024-9631 – Inefficient Algorithmic Complexity in GitLab
https://notcve.org/view.php?id=CVE-2024-9631
05 Feb 2025 — An issue was discovered in GitLab CE/EE affecting all versions starting from 13.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, where viewing diffs of MR with conflicts can be slow. • https://gitlab.com/gitlab-org/gitlab/-/issues/480867 • CWE-407: Inefficient Algorithmic Complexity •

CVE-2024-6356 – Incorrect User Management in GitLab
https://notcve.org/view.php?id=CVE-2024-6356
05 Feb 2025 — An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, which allowed cross project access for Security policy bot. • https://gitlab.com/gitlab-org/gitlab/-/issues/469108 • CWE-286: Incorrect User Management •

CVE-2025-0290 – Loop with Unreachable Exit Condition ('Infinite Loop') in GitLab
https://notcve.org/view.php?id=CVE-2025-0290
28 Jan 2025 — An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.0 prior to 17.5.5, from 17.6 prior to 17.6.3, and from 17.7 prior to 17.7.1. Under certain conditions, processing of CI artifacts metadata could cause background jobs to become unresponsive. • https://gitlab.com/gitlab-org/gitlab/-/issues/372134 • CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') •

CVE-2024-11931 – Insufficient Granularity of Access Control in GitLab
https://notcve.org/view.php?id=CVE-2024-11931
24 Jan 2025 — An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.6.4, from 17.7 prior to 17.7.3, and from 17.8 prior to 17.8.1. Under certain conditions, it may have been possible for users with developer role to exfiltrate protected CI variables via CI lint. • https://gitlab.com/gitlab-org/gitlab/-/issues/480901 • CWE-1220: Insufficient Granularity of Access Control •

CVE-2024-13041 – Incorrect User Management in GitLab
https://notcve.org/view.php?id=CVE-2024-13041
09 Jan 2025 — An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. When a user is created via the SAML provider, the external groups setting overrides the external provider configuration. As a result, the user may not be marked as external thereby giving those users access to internal projects or groups. • https://about.gitlab.com/releases/2025/01/08/patch-release-gitlab-17-7-1-released/#instance-saml-does-not-respect-external_provider-configuration • CWE-286: Incorrect User Management •

CVE-2024-6324 – Inefficient Algorithmic Complexity in GitLab
https://notcve.org/view.php?id=CVE-2024-6324
09 Jan 2025 — An issue was discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. It was possible to trigger a DoS by creating cyclic references between epics. • https://about.gitlab.com/releases/2025/01/08/patch-release-gitlab-17-7-1-released/#cyclic-reference-of-epics-leads-resource-exhaustion • CWE-407: Inefficient Algorithmic Complexity •