FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Gitlab -- Vulnerabilities

Affected packages
17.10.0 <= gitlab-ce < 17.10.4
17.9.0 <= gitlab-ce < 17.9.6
7.7.0 <= gitlab-ce < 17.8.7
17.10.0 <= gitlab-ee < 17.10.4
17.9.0 <= gitlab-ee < 17.9.6
7.7.0 <= gitlab-ee < 17.8.7

Details

VuXML ID ed602f8b-15c2-11f0-b4e4-2cf05da270f3
Discovery 2025-04-09
Entry 2025-04-10

Gitlab reports:

Denial of service via CI pipelines

Unintentionally authorizing sensitive actions on users behalf

IP Restriction Bypass through GraphQL Subscription

Unauthorized users can list the number of confidential issues

Debugging Information Disclosed

References

CVE Name CVE-2024-11129
CVE Name CVE-2025-0362
CVE Name CVE-2025-1677
CVE Name CVE-2025-2408
CVE Name CVE-2025-2469
URL https://about.gitlab.com/releases/2025/04/09/patch-release-gitlab-17-10-4-released/