Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-2256

Опубликовано: 12 сент. 2025
Источник: redhat

Описание

An issue has been discovered in GitLab CE/EE affecting all versions from 7.12 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed unauthorized users to render the GitLab instance unresponsive to legitimate users by sending multiple concurrent large SAML responses.

Дополнительная информация

Статус:

Important
Дефект:
CWE-1284
https://bugzilla.redhat.com/show_bug.cgi?id=2394755GitLab: Improper Validation of Specified Quantity in Input in GitLab

Связанные уязвимости

CVSS3: 7.5
nvd
4 месяца назад

An issue has been discovered in GitLab CE/EE affecting all versions from 7.12 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed unauthorized users to render the GitLab instance unresponsive to legitimate users by sending multiple concurrent large SAML responses.

CVSS3: 7.5
debian
4 месяца назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 7.5
github
4 месяца назад

An issue has been discovered in GitLab CE/EE affecting all versions from 7.12 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed unauthorized users to render the GitLab instance unresponsive to legitimate users by sending multiple concurrent large SAML responses.

CVSS3: 7.5
fstec
4 месяца назад

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab CE/EE, связанная с недостатками механизма ограничения количества входных данных, позволяющая нарушителю вызвать отказ в обслуживании