CVE-2025-11990
EUVD-2025-19769615.11.2025, 08:15
GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated user to gain CSRF tokens by exploiting improper input validation in repository references combined with redirect handling weaknesses.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| gitlab | gitlab | 18.4.0 ≤ 𝑥 < 18.4.4 |
| gitlab | gitlab | 18.5.0 ≤ 𝑥 < 18.5.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-177 - Improper Handling of URL Encoding (Hex Encoding)The software does not properly handle when all or part of an input has been URL encoded.
- CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')The software uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the software does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.