VDB

CVE-2025-0314

CVE-2025-0314 PUBLISHED

An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.6.4, 17.7 before 17.7.3, and 17.8 before 17.8.1. Improper rendering of certain file types lead to cross-site scripting.

EPSS 7.90% · 92.2th percentile

Risk Scores

EPSS Score
7.90%
92.2th percentile

Affected Products

VendorProductVersions
Bitnamigitlab17.8.0, 17.7.0, 17.2.0
Bitnamigitlab17.2.0, 17.8.0, 17.7.0

Timeline

  • Jan 21, 1970 Security Advisory
  • Jan 22, 2025 PoC Published
  • Jan 22, 2025 CVE Published
  • Jan 23, 2025 PoC Published
  • Jan 23, 2025 PoC Published
  • Jan 24, 2025 EPSS Score
  • Jan 24, 2025 Coalition ESS Score
  • Jan 24, 2025 PoC Published
  • Jan 24, 2025 PoC Published
  • Jan 24, 2025 PoC Published
  • Jan 24, 2025 PoC Published
  • Jan 27, 2025 PoC Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›