CVE-2025-0475 — Cross-site Scripting in Gitlab
Severity
6.1MEDIUMNVD
EPSS
1.0%
top 23.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 3
Description
An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1. A proxy feature could potentially allow unintended content rendering leading to XSS under specific circumstances.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7
Affected Packages8 packages
🔴Vulnerability Details
1GHSA▶
GHSA-wpxf-3mm2-76f8: An issue has been discovered in GitLab CE/EE affecting all versions from 15↗2025-03-03
📋Vendor Advisories
3GitLab▶
CVE-2025-0475: An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1. A prox↗2025-03-03
Debian▶
CVE-2025-0475: gitlab - An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 p...↗2025