Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-13761

Опубликовано: 09 янв. 2026
Источник: redhat
CVSS3: 8

Описание

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unauthenticated user to execute arbitrary code in the context of an authenticated user's browser by convincing the legitimate user to visit a specially crafted webpage.

A flaw was found in GitLab. This Cross-Site Scripting (XSS) vulnerability allows an unauthenticated attacker to execute arbitrary code in the context of an authenticated user's browser. This occurs when a legitimate user is convinced to visit a specially crafted webpage, potentially leading to compromised user sessions or data.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Pipelinesopenshift-pipelines/pipelines-console-plugin-rhel9Not affected
Red Hat OpenShift Container Platform 4openshift4/ose-consoleNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-console-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2428218gitlab: GitLab: Cross-Site Scripting Vulnerability Leading to Arbitrary Code Execution

8 High

CVSS3

Связанные уязвимости

CVSS3: 8
nvd
около 1 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unauthenticated user to execute arbitrary code in the context of an authenticated user's browser by convincing the legitimate user to visit a specially crafted webpage.

CVSS3: 8
debian
около 1 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 8
github
около 1 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unauthenticated user to execute arbitrary code in the context of an authenticated user's browser by convincing the legitimate user to visit a specially crafted webpage.

8 High

CVSS3