CVE-2025-1908

CVSS 3.1 Score 7.7 of 10 (high)

Details

Published Apr 24, 2025
Updated: Apr 29, 2025
CWE ID 840

Summary

CVE-2025-1908 is a vulnerability affecting GitLab Enterprise Edition (EE) and Community Edition (CE), allowing attackers to track users' browsing activities. This issue, present in versions 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1, could potentially lead to full account take-over. By exploiting this flaw, an attacker may gain unauthorized access to a user's account, posing a significant security risk. The exact nature of the vulnerability is not specified, but users are advised to update their GitLab installations to the latest available versions to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share