CVE-2025-5101

An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that under certain conditions could have allowed an authenticated attacker to distribute malicious code that appears harmless in the web interface by taking advantage of ambiguity between branches and tags during repository imports.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:18.3.0:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:18.3.0:*:*:*:enterprise:*:*:*

History

02 Sep 2025, 17:47

Type Values Removed Values Added
CPE cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:18.3.0:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:18.3.0:*:*:*:enterprise:*:*:*
References () https://gitlab.com/gitlab-org/gitlab/-/issues/545165 - () https://gitlab.com/gitlab-org/gitlab/-/issues/545165 - Broken Link
References () https://hackerone.com/reports/3124199 - () https://hackerone.com/reports/3124199 - Permissions Required
First Time Gitlab gitlab
Gitlab

29 Aug 2025, 16:24

Type Values Removed Values Added
Summary
  • (es) Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones anteriores a la 18.1.5, 18.2 anteriores a la 18.2.5 y 18.3 anteriores a la 18.3.1 que, en determinadas condiciones, podría haber permitido a un atacante autenticado distribuir código malicioso que parece inofensivo en la interfaz web aprovechando la ambigüedad entre ramas y etiquetas durante las importaciones del repositorio.

27 Aug 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-27 20:15

Updated : 2025-09-02 17:47


NVD link : CVE-2025-5101

Mitre link : CVE-2025-5101

CVE.ORG link : CVE-2025-5101


JSON object : View

Products Affected

gitlab

  • gitlab
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')