vulnerability
FreeBSD: VID-1a8c5720-e9cf-11ef-9e96-2cf05da270f3 (CVE-2024-9870): Gitlab -- Vulnerabilities
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 4 | (AV:N/AC:L/Au:S/C:P/I:N/A:N) | Feb 13, 2025 | Feb 14, 2025 | Dec 10, 2025 |
Severity
4
CVSS
(AV:N/AC:L/Au:S/C:P/I:N/A:N)
Published
Feb 13, 2025
Added
Feb 14, 2025
Modified
Dec 10, 2025
Description
Gitlab reports: A CSP-bypass XSS in merge-request page Denial of Service due to Unbounded Symbol Creation Exfiltrate content from private issues using Prompt Injection A custom permission may allow overriding Repository settings Internal HTTP header leak via route confusion in workhorse SSRF via workspaces Unauthorized Incident Closure and Deletion by Planner Role in GitLab ActionCable does not invalidate tokens after revocation
Solutions
freebsd-upgrade-package-gitlab-cefreebsd-upgrade-package-gitlab-ee
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.