VDB
WID-SEC-W-2025-2140
WID-SEC-W-2025-2140
PUBLISHED
CVSS 8.699999809265137 HIGH
GitLab ist eine Webanwendung zur Versionsverwaltung für Softwareprojekte auf Basis von git.
Risk Scores
CVSS v4.0
8.699999809265137
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Open Source GitLab <18.4.1 | ||
| Open Source GitLab 18.3.3 | ||
| Open Source GitLab 18.2.7 | ||
| Open Source GitLab <18.3.3 | ||
| Open Source GitLab <18.2.7 | ||
| Open Source GitLab 18.4.1 |
Exploit Intelligence
- PoC de RCE en PostgreSQL — CVE-2025-8714 (github-poc)
- https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-2140.json (circl)
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-2140 (circl)
- https://about.gitlab.com/releases/2025/09/25/patch-release-gitlab-18-4-1-released/ (circl)
- dbutil.go (github-poc)
- context.go (github-poc)
- schema_cleaner_spec.rb (github-poc)
- ghost_report_20260112_192608.json (github-poc)
- ghost_report_20260112_175243.json (github-poc)
- ghost_report_20260112_182220.json (github-poc)
Timeline
- Sep 25, 2025 CVE Published
- Sep 28, 2025 CVE Updated