Skip to content

Commit 6bfa3ea

Browse files

File tree

6 files changed

+250
-0
lines changed

6 files changed

+250
-0
lines changed
Lines changed: 42 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,42 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-28w7-9227-5wcm",
4+
"modified": "2025-10-27T00:30:50Z",
5+
"published": "2025-10-27T00:30:50Z",
6+
"aliases": [
7+
"CVE-2025-6601"
8+
],
9+
"details": "GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.3, and 18.5 before 18.5.1 that under certain conditions could have allowed authenticated users to gain unauthorized project access by exploiting the access request approval workflow.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N"
14+
}
15+
],
16+
"affected": [],
17+
"references": [
18+
{
19+
"type": "ADVISORY",
20+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-6601"
21+
},
22+
{
23+
"type": "WEB",
24+
"url": "https://hackerone.com/reports/3209641"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://about.gitlab.com/releases/2025/10/22/patch-release-gitlab-18-5-1-released"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://gitlab.com/gitlab-org/gitlab/-/issues/551267"
33+
}
34+
],
35+
"database_specific": {
36+
"cwe_ids": [],
37+
"severity": "LOW",
38+
"github_reviewed": false,
39+
"github_reviewed_at": null,
40+
"nvd_published_at": "2025-10-27T00:15:41Z"
41+
}
42+
}
Lines changed: 40 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,40 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-5qhc-78h9-5m5x",
4+
"modified": "2025-10-27T00:30:50Z",
5+
"published": "2025-10-27T00:30:50Z",
6+
"aliases": [
7+
"CVE-2025-11989"
8+
],
9+
"details": "GitLab has remediated an issue in GitLab EE affecting all versions from 17.6.0 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker to execute unauthorized quick actions by including malicious commands in specific descriptions.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N"
14+
}
15+
],
16+
"affected": [],
17+
"references": [
18+
{
19+
"type": "ADVISORY",
20+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-11989"
21+
},
22+
{
23+
"type": "WEB",
24+
"url": "https://about.gitlab.com/releases/2025/10/22/patch-release-gitlab-18-5-1-released"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://gitlab.com/gitlab-org/security/gitlab/-/issues/1426"
29+
}
30+
],
31+
"database_specific": {
32+
"cwe_ids": [
33+
"CWE-862"
34+
],
35+
"severity": "LOW",
36+
"github_reviewed": false,
37+
"github_reviewed_at": null,
38+
"nvd_published_at": "2025-10-27T00:15:40Z"
39+
}
40+
}
Lines changed: 40 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,40 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-jgp3-92wq-g4pq",
4+
"modified": "2025-10-27T00:30:50Z",
5+
"published": "2025-10-27T00:30:50Z",
6+
"aliases": [
7+
"CVE-2025-11971"
8+
],
9+
"details": "GitLab has remediated an issue in GitLab EE affecting all versions from 10.6 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker to trigger unauthorized pipeline executions by manipulating commits.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:L/A:N"
14+
}
15+
],
16+
"affected": [],
17+
"references": [
18+
{
19+
"type": "ADVISORY",
20+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-11971"
21+
},
22+
{
23+
"type": "WEB",
24+
"url": "https://about.gitlab.com/releases/2025/10/22/patch-release-gitlab-18-5-1-released"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://gitlab.com/gitlab-org/gitlab/-/issues/566587"
29+
}
30+
],
31+
"database_specific": {
32+
"cwe_ids": [
33+
"CWE-863"
34+
],
35+
"severity": "MODERATE",
36+
"github_reviewed": false,
37+
"github_reviewed_at": null,
38+
"nvd_published_at": "2025-10-27T00:15:40Z"
39+
}
40+
}
Lines changed: 40 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,40 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-rcvw-fc36-wjhj",
4+
"modified": "2025-10-27T00:30:50Z",
5+
"published": "2025-10-27T00:30:50Z",
6+
"aliases": [
7+
"CVE-2025-11974"
8+
],
9+
"details": "GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.7 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to create a denial of service condition by uploading large files to specific API endpoints.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
14+
}
15+
],
16+
"affected": [],
17+
"references": [
18+
{
19+
"type": "ADVISORY",
20+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-11974"
21+
},
22+
{
23+
"type": "WEB",
24+
"url": "https://about.gitlab.com/releases/2025/10/22/patch-release-gitlab-18-5-1-released"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://gitlab.com/gitlab-org/gitlab/-/issues/571761"
29+
}
30+
],
31+
"database_specific": {
32+
"cwe_ids": [
33+
"CWE-770"
34+
],
35+
"severity": "MODERATE",
36+
"github_reviewed": false,
37+
"github_reviewed_at": null,
38+
"nvd_published_at": "2025-10-27T00:15:40Z"
39+
}
40+
}
Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,44 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-w2m4-xx67-836j",
4+
"modified": "2025-10-27T00:30:49Z",
5+
"published": "2025-10-27T00:30:49Z",
6+
"aliases": [
7+
"CVE-2025-10497"
8+
],
9+
"details": "GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to cause a denial of service condition by sending specially crafted payloads.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
14+
}
15+
],
16+
"affected": [],
17+
"references": [
18+
{
19+
"type": "ADVISORY",
20+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-10497"
21+
},
22+
{
23+
"type": "WEB",
24+
"url": "https://hackerone.com/reports/3338151"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://about.gitlab.com/releases/2025/10/22/patch-release-gitlab-18-5-1-released"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://gitlab.com/gitlab-org/gitlab/-/issues/570336"
33+
}
34+
],
35+
"database_specific": {
36+
"cwe_ids": [
37+
"CWE-770"
38+
],
39+
"severity": "HIGH",
40+
"github_reviewed": false,
41+
"github_reviewed_at": null,
42+
"nvd_published_at": "2025-10-27T00:15:39Z"
43+
}
44+
}
Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,44 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-xgjv-46p6-hwgv",
4+
"modified": "2025-10-27T00:30:49Z",
5+
"published": "2025-10-27T00:30:49Z",
6+
"aliases": [
7+
"CVE-2025-11447"
8+
],
9+
"details": "GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.0 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to cause a denial of service condition by sending GraphQL requests with crafted JSON payloads.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
14+
}
15+
],
16+
"affected": [],
17+
"references": [
18+
{
19+
"type": "ADVISORY",
20+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-11447"
21+
},
22+
{
23+
"type": "WEB",
24+
"url": "https://hackerone.com/reports/3367019"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://about.gitlab.com/releases/2025/10/22/patch-release-gitlab-18-5-1-released"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://gitlab.com/gitlab-org/gitlab/-/issues/574858"
33+
}
34+
],
35+
"database_specific": {
36+
"cwe_ids": [
37+
"CWE-770"
38+
],
39+
"severity": "HIGH",
40+
"github_reviewed": false,
41+
"github_reviewed_at": null,
42+
"nvd_published_at": "2025-10-27T00:15:40Z"
43+
}
44+
}

0 commit comments

Comments
 (0)