HomeUpdatesDevSecOps: GitLab fixes multiple vulnerabilities

DevSecOps: GitLab patches multiple vulnerabilities

GitLab announced the release of security updates for its DevSecOps platform , addressing multiple vulnerabilities that could allow malicious users to gain access to accounts and insert malicious jobs into future pipelines.

GitLab vulnerabilities DevSecOps

GitLab Community and Enterprise Edition versions 18.0.2, 17.11.4, and 17.10.8 are now available, and the company is urging all administrators to upgrade immediately. GitLab.com is already running the updated version. GitLab Dedicated customers don't need to do anything.

See also: Palo Alto Networks patches two zero-day firewall vulnerabilities

Among the vulnerabilities fixed, CVE-2025-4278, which allows malicious code to be embedded in search pages, paving the way for gaining account control.

Additionally, GitLab has fixed CVE-2025-5121, an issue in GitLab Ultimate EE. The vulnerability allows remote attackers to inject malicious CI/CD jobs into future CI/CD pipelines of various projects.

GitLab emphasizes that the attacks require authenticated access to GitLab instances with a GitLab Ultimate license.

See also: Hackers exploit zero-day vulnerability in Windows WebDav

As part of its broader security efforts, GitLab announced the resolution of two more significant vulnerabilities in its platform. The first is a cross-site scripting (CVE-2025-2254), which could allow attackers to perform actions on behalf of a legitimate user. The second is a denial of service (CVE-2025-0673), which could cause uncontrolled redirect loops, leading to resource exhaustion and access interruption for normal users.

DevSecOps: GitLab patches multiple vulnerabilities

Hackers target GitLab

The increased targeting of the platform by malicious actors is not surprising, as GitLab repositories often host critical information, such as code and credentials. In fact, recent breaches at organizations such as Europcar Mobility Group and education giant Pearson have been attributed to vulnerabilities in their GitLab repos.

GitLab's correction of the above vulnerabilities is a positive and necessary step towards maintaining the trust of its users and protecting its platform against increasingly sophisticated threats.

See also: Fortinet and Ivanti patch high-severity vulnerabilities

The importance of DevSecOps platform security is enormous, given that GitLab serves over 30 million users worldwide and is a core tool for over 50% of Fortune 100 companies. Among them are top names such as Goldman Sachs, Airbus, T-Mobile, Lockheed Martin, Nvidia, and UBS.

Most importantly, GitLab acted promptly, providing security updates for vulnerabilities that could have serious consequences — such as account takeover, malicious pipeline injection, or denial-of-service via resource exhaustion. These threats are not theoretical; in a DevSecOps environment where critical data is stored, any breach can have ripple effects across entire businesses.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS