An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that under certain conditions could have allowed an authenticated attacker to distribute malicious code that appears harmless in the web interface by taking advantage of ambiguity between branches and tags during repository imports.
References
Link | Resource |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/545165 | Broken Link |
https://hackerone.com/reports/3124199 | Permissions Required |
Configurations
Configuration 1 (hide)
|
History
02 Sep 2025, 17:47
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* cpe:2.3:a:gitlab:gitlab:18.3.0:*:*:*:community:*:*:* cpe:2.3:a:gitlab:gitlab:18.3.0:*:*:*:enterprise:*:*:* |
|
References | () https://gitlab.com/gitlab-org/gitlab/-/issues/545165 - Broken Link | |
References | () https://hackerone.com/reports/3124199 - Permissions Required | |
First Time |
Gitlab gitlab
Gitlab |
29 Aug 2025, 16:24
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
27 Aug 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-27 20:15
Updated : 2025-09-02 17:47
NVD link : CVE-2025-5101
Mitre link : CVE-2025-5101
CVE.ORG link : CVE-2025-5101
JSON object : View
Products Affected
gitlab
- gitlab
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')