Categories: Cyber Security News

GitLab Releases Security Patch for Multiple Vulnerabilities

GitLab has released critical security patches across three versions – 18.2.1, 18.1.3, and 18.0.5 – addressing multiple high and medium-severity vulnerabilities affecting both Community Edition (CE) and Enterprise Edition (EE).

The company strongly recommends immediate upgrades for all self-managed installations, while GitLab.com is already running the patched versions.

Critical Security Vulnerabilities Addressed

The patch release addresses six significant security vulnerabilities, with two classified as high-severity cross-site scripting (XSS) issues.

Sponsored

The most critical vulnerability, CVE-2025-4700, impacts the Kubernetes proxy feature and could allow attackers to trigger unintended content rendering, leading to XSS attacks.

This vulnerability affects all versions from 15.10 before the current patches and carries a CVSS score of 8.7.

A second high-severity vulnerability, CVE-2025-4439, affects installations using content delivery networks (CDNs) and could enable authenticated users to perform cross-site scripting attacks.

This issue has a CVSS score of 7.7 and impacts the same version range as the primary XSS vulnerability.

Medium-Severity Issues and Access Control Problems

Four medium-severity vulnerabilities were also patched, primarily involving improper access control and exposure of sensitive information.

CVE-2025-7001 addressed unauthorized access to resource group information through the API, while CVE-2025-4976 specifically impacts GitLab Enterprise Edition by potentially exposing internal notes in GitLab Duo responses.

Additional medium-severity fixes include CVE-2025-0765, which prevented unauthorized access to custom service desk email addresses, and CVE-2025-1299, addressing unauthorized access to deployment job logs through crafted requests.

Bug Fixes and Improvements

Beyond security patches, the releases include numerous bug fixes across all three versions.

Sponsored

Notable improvements in version 18.2.1 include fixes for S3 compatibility in Workhorse uploads for non-AWS providers and enhancements to the Agentic Chat feature.

Version 18.1.3 addresses Elasticsearch configuration issues and branch loading problems in group merge request lists, while version 18.0.5 focuses on search functionality improvements and container registry updates.

Immediate Action Required

GitLab emphasizes that all affected installations should upgrade immediately to maintain security hygiene.

The company follows a bi-monthly scheduled release pattern on the second and fourth Wednesdays, though critical vulnerabilities may trigger ad-hoc releases.

Security vulnerability details will be made public on GitLab’s issue tracker 30 days after the patch release, following standard disclosure practices.

GitLab Dedicated customers do not need to take action as updates are managed automatically, while self-managed users should consult the official update documentation for their specific deployment type.

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates

The post GitLab Releases Security Patch for Multiple Vulnerabilities appeared first on Cyber Security News.

rssfeeds-admin

Recent Posts

Microsoft Tracks Storm-2561 In Fake VPN Client Credential Theft Scheme

Microsoft says a cybercriminal group it tracks as Storm-2561 is running a credential theft campaign…

20 minutes ago

Microsoft to Block Windows 11 and Server 2025 Automated Installation After Critical RCE Vulnerability

Microsoft has announced a two-phase plan to disable the hands-free deployment feature in Windows Deployment…

41 minutes ago

Primal Season 3 Finale Review: Spear Vs… Everyone?

Full spoilers follow for Primal Season 3, Episode 10, “An Echo of Eternity,” which is…

2 hours ago

A First Look at the Universe of Futuristic MMORPG Prism 2033

The year is 2033, and a devastating virus and rogue AI have combined to bring…

4 hours ago

A First Look at the Universe of Futuristic MMORPG Prism 2033

The year is 2033, and a devastating virus and rogue AI have combined to bring…

4 hours ago

The 7th Tie in Oscars History Just Happened for Best Live Action Short Film

The Oscars just had their seventh tie in the history of the Academy Awards, for…

5 hours ago

This website uses cookies.