An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass in a user's browser under specific conditions, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.
Metrics
Affected Vendors & Products
References
History
Fri, 30 May 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 30 May 2025 11:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass in a user's browser under specific conditions, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1. | |
Title | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab | |
First Time appeared |
Gitlab
Gitlab gitlab |
|
Weaknesses | CWE-79 | |
CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | |
Vendors & Products |
Gitlab
Gitlab gitlab |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitLab
Published: 2025-05-30T11:02:36.384Z
Updated: 2025-05-30T12:50:13.554Z
Reserved: 2025-02-27T17:30:47.380Z
Link: CVE-2025-1763

Updated: 2025-05-30T12:50:07.325Z

Status : Awaiting Analysis
Published: 2025-05-30T11:15:20.213
Modified: 2025-05-30T16:31:03.107
Link: CVE-2025-1763

No data.