diff --git a/security/vuxml/files/tidy.xsl b/security/vuxml/files/tidy.xsl index 41f3532cf1e3..c890e51e0d72 100644 --- a/security/vuxml/files/tidy.xsl +++ b/security/vuxml/files/tidy.xsl @@ -47,6 +47,7 @@ result in more namespace declarations than we wish. + ]> ]]> diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 6fd3b10b8c3c..ba7314a9e226 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -22,6 +22,7 @@ + ]> +&vuln-2025; &vuln-2024; &vuln-2023; &vuln-2022; diff --git a/security/vuxml/vuln/2025.xml b/security/vuxml/vuln/2025.xml new file mode 100644 index 000000000000..5588926228b8 --- /dev/null +++ b/security/vuxml/vuln/2025.xml @@ -0,0 +1,34 @@ + + Gitlab -- Vulnerabilities + + + gitlab-ce + gitlab-ee + 17.7.017.7.1 + 17.6.017.6.3 + 11.0.017.5.5 + + + + +

Gitlab reports:

+
+

Possible access token exposure in GitLab logs

+

Cyclic reference of epics leads resource exhaustion

+

Unauthorized user can manipulate status of issues in public projects

+

Instance SAML does not respect external_provider configuration

+
+ +
+ + CVE-2025-0194 + CVE-2024-6324 + CVE-2024-12431 + CVE-2024-13041 + https://about.gitlab.com/releases/2025/01/08/patch-release-gitlab-17-7-1-released/ + + + 2025-01-08 + 2025-01-08 + +