CVE-2025-0376

EUVD-2025-1636
An XSS vulnerability exists in GitLab CE/EE affecting all versions from 13.3 prior to 17.6.5, 17.7 prior to 17.7.4 and 17.8 prior to 17.8.2 that allows an attacker to execute unauthorized actions via a change page.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.7 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
GitLabCNA
8.7 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 83%
Affected Products (NVD)
VendorProductVersion
gitlabgitlab
13.3.0 ≤
𝑥
< 17.6.5
gitlabgitlab
13.3.0 ≤
𝑥
< 17.6.5
gitlabgitlab
17.7.0 ≤
𝑥
< 17.7.4
gitlabgitlab
17.7.0 ≤
𝑥
< 17.7.4
gitlabgitlab
17.8.0 ≤
𝑥
< 17.8.2
gitlabgitlab
17.8.0 ≤
𝑥
< 17.8.2
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gitlab
focal
dne
jammy
dne
noble
dne
oracular
dne
xenial
ignored