CVE-2025-4278 - CERT CVE
ID CVE-2025-4278
Sažetak An issue has been discovered in GitLab CE/EE affecting all versions starting with 18.0 before 18.0.2. Under certain conditions html injection in new search page could lead to account takeover.
Reference
CVSS
Base: 8.7
Impact: 5.8
Exploitability:2.3
Pristup
VektorSloženostAutentikacija
NETWORK LOW LOW
Impact
PovjerljivostCjelovitostDostupnost
HIGH HIGH NONE
CVSS vektor CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Zadnje važnije ažuriranje 12-06-2025 - 16:06
Objavljeno 12-06-2025 - 10:16