CVE-2025-0475Cross-site Scripting in Gitlab

Severity
6.1MEDIUMNVD
EPSS
1.0%
top 23.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 3

Description

An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1. A proxy feature could potentially allow unintended content rendering leading to XSS under specific circumstances.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages8 packages

CVEListV5gitlab/gitlab15.1017.7.6+2
NVDgitlab/gitlab15.10.017.7.6+2
debiandebian/gitlab
gitlabgitlab/gitlab

🔴Vulnerability Details

1
GHSA
GHSA-wpxf-3mm2-76f8: An issue has been discovered in GitLab CE/EE affecting all versions from 152025-03-03

📋Vendor Advisories

3
GitLab
CVE-2025-0475: An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1. A prox2025-03-03
Debian
CVE-2025-0475: gitlab - An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 p...2025
Microsoft
Go-Getter Vulnerable to Decompression Bombs2023-02-14