CVE-2025-0362
An issue has been discovered in GitLab CE/EE affecting all versions from 7.7 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions, an attacker could potentially trick users into unintentionally authorizing sensitive actions on their behalf.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.4
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N
- EPSS probability
- 0.30%
- CWE
- CWE-1021
- Published
- 2025-04-10
- Last modified
- 2026-03-13
Affected products
- GitLab GitLab
- GitLab GitLab
- GitLab GitLab
Weakness type
Related vulnerabilities
- CVE-2026-87995 — Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin
- CVE-2026-87538 — Clickjacking in Input in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had...
- CVE-2026-87655 — Clickjacking in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker...
- CVE-2026-87486 — Clickjacking in TrustedWebActivities in Google Chrome on on Android prior to 153.0.8010.36 allowed...
- CVE-2026-75548 — Ebyte NA111-M Improper Restriction of Rendered UI Layers or Frames
- CVE-2026-18534 — Address bar spoofing risk in affected iOS versions of Arc Search
- CVE-2026-44762 — Security Misconfiguration in SAP Data Services Management Console
- CVE-2026-70608 — Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path