CVE-2025-0314

Published Jan 24, 2025

Last updated a month ago

Overview

Description
An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.6.4, 17.7 before 17.7.3, and 17.8 before 17.8.1. Improper rendering of certain file types lead to cross-site scripting.
Source
cve@gitlab.com
NVD status
Received

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.7
Impact score
5.8
Exploitability score
2.3
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Severity
HIGH

Weaknesses

cve@gitlab.com
CWE-79

Social media

Hype score
Not currently trending
  1. به تازگی برای GITLAB سه آسیب پذیری با کدهای شناسایی CVE-2025-0314 از نوع xss و CVE-2024-11931 و CVE-2024-6324 که از نوع DOS می باشد ، منتشر شده است. برای پیشگیری و مقابله با این تهدیدات ، به نسخه 17.6.4 یا 17.7.3 به روز رسانی نمایید. https://t.co/Poz3aKY03t https://t.co/wjUdarPR

    @AmirHossein_sec

    30 Jan 2025

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2025-0314 (CVSS:8.7, HIGH) is Awaiting Analysis. An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.6.4, 17.7 before 17.7.3, and 17...https://t.co/0vUv1lJ8ev #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    29 Jan 2025

    14 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  3. GitLab has released critical updates for versions 17.8.1, 17.7.3, and 17.6.4 to fix multiple vulnerabilities, including a severe XSS flaw (CVE-2025-0314). Update now! 🔒🛡️ #GitLab #XSS #USA link: https://t.co/BY1QZYae28 https://t.co/2jl9zWTxBr

    @TweetThreatNews

    24 Jan 2025

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 【リンク集:1月23日〜24日のセキュリティ関連ニュース/記事】 <脆弱性> ・シスコ、Meeting Managementにおける重大な権限昇格の脆弱性を修正(CVE -2025-20156、CVSS 9.9) https://t.co/porqgYKPGk ・CVE-2025-0314:GitLabがXSS脆弱性のパッチをリリース https://t.co/putaDwxPc5… https://t.co/PTvD8feaBr

    @MachinaRecord

    24 Jan 2025

    87 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  5. [CVE-2025-0314: HIGH] URGENT: GitLab CE/EE versions 17.2-17.6.4, 17.7-17.7.3, & 17.8-17.8.1 found vulnerable to cross-site scripting due to file rendering. Update to stay secure. #cybersecurity#cybersecurity,#vulnerability https://t.co/PRdzXGcsZT https://t.co/wQHK4O3mvJ

    @CveFindCom

    24 Jan 2025

    75 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CVE-2025-0314 impacts GitLab #Gitlab #CVE-2025-0314 https://t.co/FKmRE1xpAo

    @pravin_karthik

    23 Jan 2025

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. CVE-2025-0314: GitLab Releases Patch for XSS Exploit GitLab security update: Addressing multiple vulnerabilities, including the high severity cross-site scripting flaw (CVE-2025-0314). Stay protected! https://t.co/cANvI2kAHX

    @the_yellow_fall

    23 Jan 2025

    30 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes