vulnerability

FreeBSD: VID-a1a1b0c2-3791-11f0-8600-2cf05da270f3 (CVE-2025-0605): Gitlab -- vulnerabilities

Severity
5
CVSS
(AV:N/AC:M/Au:S/C:P/I:P/A:N)
Published
May 23, 2025
Added
May 24, 2025
Modified
Mar 25, 2026

Description

Gitlab reports: Unprotected large blob endpoint in GitLab allows Denial of Service Improper XPath validation allows modified SAML response to bypass 2FA requirement A Discord webhook integration may cause DoS Unbounded Kubernetes cluster tokens may lead to DoS Unvalidated notes position may lead to Denial of Service Hidden/masked variables may get exposed in the UI Two-factor authentication requirement bypass View full email addresses that should be partially obscured Branch name confusion in confidential MRs Unauthorized access to job data via a GraphQL query

Solutions

freebsd-upgrade-package-gitlab-cefreebsd-upgrade-package-gitlab-ee
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.