PT-2025-47048 · Gitlab · Gitlab Ce/Ee

Published

2025-11-12

·

Updated

2025-11-15

·

CVE-2025-11990

CVSS v3.1

3.5

Low

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions GitLab EE versions 18.4 through 18.4.3 GitLab EE versions 18.5 through 18.5.1
Description An authenticated user could obtain CSRF tokens due to improper input validation in repository references and redirect handling weaknesses. The issue involves the exploitation of repository references.
Recommendations Update GitLab EE to version 18.4.4 or later. Update GitLab EE to version 18.5.2 or later.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2025-14459
BIT-GITLAB-2025-11990
CVE-2025-11990

Affected Products

Gitlab Ce/Ee