VDB
CVE-2025-0376
CVE-2025-0376
PUBLISHED
An XSS vulnerability exists in GitLab CE/EE affecting all versions from 13.3 prior to 17.6.5, 17.7 prior to 17.7.4 and 17.8 prior to 17.8.2 that allows an attacker to execute unauthorized actions via a change page.
EPSS 3.18% · 87.2th percentile
Risk Scores
EPSS Score
3.18%
87.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | gitlab | 13.3.0 |
| Bitnami | gitlab | 13.3.0 |
Timeline
- Jan 21, 1970 Security Advisory
- Feb 11, 2025 CVE Published
- Feb 12, 2025 PoC Published
- Feb 12, 2025 PoC Published
- Feb 12, 2025 PoC Published
- Feb 12, 2025 PoC Published
- Feb 13, 2025 EPSS Score
- Feb 13, 2025 PoC Published
- Feb 27, 2025 EPSS Score
- Mar 2, 2025 Coalition ESS Score
- Mar 5, 2025 CVE Updated
- Mar 18, 2025 Coalition ESS Score