VDB
CVE-2025-1198
CVE-2025-1198
PUBLISHED
An issue discovered in GitLab CE/EE affecting all versions from 16.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 meant that long-lived connections in ActionCable potentially allowed revoked Personal Access Tokens access to streaming results.
EPSS 0.02% · 7.0th percentile
Risk Scores
EPSS Score
0.02%
7.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | gitlab | 16.11.0 |
| Bitnami | gitlab | 16.11.0 |
Timeline
- Jan 21, 1970 Security Advisory
- Feb 11, 2025 CVE Published
- Feb 13, 2025 EPSS Score
- Feb 13, 2025 Coalition ESS Score
- Feb 13, 2025 PoC Published
- Feb 13, 2025 PoC Published
- Feb 13, 2025 PoC Published
- Feb 13, 2025 PoC Published
- Feb 14, 2025 PoC Published
- Feb 27, 2025 EPSS Score
- Mar 5, 2025 CVE Updated
- Mar 14, 2025 EPSS Score