GitLab has released a security advisory, urging all self-managed installations to upgrade to versions 17.9.1, 17.8.4, or 17.7.6 due to critical vulnerabilities, including serious Cross-Site Scripting (XSS) issues that may compromise user data.
The Kubernetes proxy vulnerability (CVE-2025-0475) has a CVSS score of 8.7, signifying a high risk. It affects all versions prior to the patched releases starting from 15.10. GitLab notes that this flaw might enable unintended content rendering, leading to XSS attacks. Attackers could exploit this to inject malicious code into a user’s browser, risking credential theft and other malicious activities.
By infosecbulletin
/ Thursday , February 27 2025
Cisco has warned of a critical vulnerability, CVE-2025-20111, in several Nexus switch models. This flaw could let attackers remotely crash...
Read More
By infosecbulletin
/ Thursday , February 27 2025
GitLab has released a security advisory, urging all self-managed installations to upgrade to versions 17.9.1, 17.8.4, or 17.7.6 due to...
Read More
By infosecbulletin
/ Thursday , February 27 2025
A China-linked botnet is targeting Microsoft 365 accounts with widespread password spraying attacks, according to a report by SecurityScorecard. A...
Read More
By infosecbulletin
/ Wednesday , February 26 2025
A breach notification site has added millions of new passwords and email addresses obtained from infostealer malware. Troy Hunt, founder of...
Read More
By infosecbulletin
/ Wednesday , February 26 2025
Cybersecurity researchers have discovered a campaign exploiting a remote command execution vulnerability, CVE-2023-20118, in Cisco Small Business Routers. This vulnerability...
Read More
By infosecbulletin
/ Wednesday , February 26 2025
CISA has added two critical vulnerabilities to its Known Exploited Vulnerabilities catalog, urging organizations to quickly patch their systems to...
Read More
By infosecbulletin
/ Tuesday , February 25 2025
A new cyber campaign called GitVenom poses a serious risk to developers. Security researchers found over 200 fake GitHub repositories...
Read More
By infosecbulletin
/ Tuesday , February 25 2025
Residents of Dubai can now easily renew their visas with the new AI-powered digital platform launched by the General Directorate...
Read More
By infosecbulletin
/ Tuesday , February 25 2025
CVE-2024-20953 is a vulnerability in Oracle Agile PLM, a product lifecycle management tool. With a CVSS score of 8.8, it...
Read More
By infosecbulletin
/ Monday , February 24 2025
Days after the biggest crypto hack ever, another platform has experienced a major exploit. Infini Earn, a decentralized stablecoin bank,...
Read More
A high-severity XSS vulnerability (CVE-2025-0555) with a CVSS score of 7.7 impacts the Maven Dependency Proxy in GitLab-EE. It affects versions 16.6 and earlier, allowing attackers to bypass security controls and execute arbitrary scripts in a user’s browser under certain conditions.
In addition to the XSS flaws, GitLab has addressed several other security issues:
CVE-2024-8186: A medium-severity vulnerability (CVSS 5.4) permits HTML injection in child item searches, potentially leading to XSS.
CVE-2024-10925: A medium-severity vulnerability (CVSS 5.3) allows guest users to access security policy YAML files.
A medium-severity vulnerability (CVSS 4.3) allows users with limited access to read sensitive project analytics in private projects. (CVE-2025-0307)
Administrators should update their GitLab instances to the latest compatible version.
“We strongly recommend that all installations running a version affected by the issues described below are upgraded to the latest version as soon as possible,” GitLab emphasized.
Botnet Powered by 130,000 Devices Targets Microsoft 365 Accounts