GitLab, the widely adopted DevOps platform, has announced the immediate release of versions 17.8.1, 17.7.3, and 17.6.4 for both its Community Edition (CE) and Enterprise Edition (EE).
These updates address multiple security vulnerabilities and provide critical fixes, underscoring GitLab’s commitment to maintaining the highest security standards.
The vulnerabilities addressed in these updates include a high-severity Stored XSS via Asciidoctor render, a medium-severity issue where a developer could exfiltrate protected CI/CD variables via CI lint, and another medium-severity vulnerability involving cyclic references of epics leading to resource exhaustion.
GitLab strongly encourages self-managed users to upgrade to the latest versions immediately to safeguard their systems.
Are you from SOC/DFIR Teams? - Analyse Malware Files & Links with ANY.RUN Sandox -> Try for Free
1. Stored XSS via Asciidoctor Render – CVE-2025-0314
2. Developer Could Exfiltrate Protected CI/CD Variables via CI Lint – CVE-2024-11931
3. Cyclic Reference of Epics Leads to Resource Exhaustion – CVE-2024-6324
GitLab has already deployed these updates on GitLab.com, meaning users on the hosted platform are automatically protected. GitLab Dedicated customers do not need to take action. However, self-managed GitLab users are urged to:
GitLab remains steadfast in prioritizing security by addressing vulnerabilities through timely patches.
Security issues are made public 30 days after patch releases to ensure transparency while protecting vulnerabilities during the critical update window.
Integrating Application Security into Your CI/CD Workflows Using Jenkins & Jira -> Free Webinar
National Cyber Security Centre (NCSC) has issued technical guidance following a series of cyber attacks…
Claude AI, developed by Anthropic, has been exploited by malicious actors in a range of…
As Tax Day on April 15 approaches, a alarming cybersecurity threat has emerged targeting U.S.…
Insikt Group has uncovered two new malware families, TerraStealerV2 and TerraLogger, attributed to the notorious…
MintsLoader, a malicious loader first observed in 2024, has emerged as a formidable tool in…
Cybercriminals are intensifying their efforts to undermine multi-factor authentication (MFA) through adversary-in-the-middle (AiTM) attacks, leveraging…