FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Gitlab -- vulnerabilities

Affected packages
18.6.0 <= gitlab-ce < 18.6.2
18.5.0 <= gitlab-ce < 18.5.4
6.3.0 <= gitlab-ce < 18.4.6
18.6.0 <= gitlab-ee < 18.6.2
18.5.0 <= gitlab-ee < 18.5.4
6.3.0 <= gitlab-ee < 18.4.6

Details

VuXML ID c6c9306e-d645-11f0-8ce2-2cf05da270f3
Discovery 2025-12-10
Entry 2025-12-11

Gitlab reports:

Cross-site scripting issue in Wiki impacts GitLab CE/EE

Improper encoding in vulnerability reports impacts GitLab CE/EE

Cross-site scripting issue in Swagger UI impacts GitLab CE/EE

Denial of service issue in GraphQL endpoints impacts GitLab CE/EE

Authentication bypass issue for WebAuthn users impacts GitLab CE/EE

Denial of service issue in ExifTool processing impacts GitLab CE/EE

Denial of service issue in Commit API impacts GitLab CE/EE

Information disclosure issue in compliance frameworks impacts GitLab EE

Information disclosure through error messages impacts GitLab CE/EE

HTML injection issue in merge request titles impacts GitLab CE/EE

References

CVE Name CVE-2025-11247
CVE Name CVE-2025-11984
CVE Name CVE-2025-12029
CVE Name CVE-2025-12562
CVE Name CVE-2025-12716
CVE Name CVE-2025-12734
CVE Name CVE-2025-13978
CVE Name CVE-2025-14157
CVE Name CVE-2025-4097
CVE Name CVE-2025-8405
URL https://about.gitlab.com/releases/2025/12/10/patch-release-gitlab-18-6-2-released/