83 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2025-6601
GitLab DevOps
2.7
LOW
EPSS
0.0%
2025 CWE-840 1 PoC

GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.3, and 18.5 before 18.5.1 that under certain conditions could have allowed authenticated users to gain unauthorized project access by exploiting the access request approval workflow.

CVE-2025-6168
GitLab DevOps Web
2.7
LOW
EPSS
0.1%
2025 CWE-863 1 PoC

An issue has been discovered in GitLab EE affecting all versions from 18.0 before 18.0.4 and 18.1 before 18.1.2 that could have allowed authenticated maintainers to bypass group-level user invitation restrictions by sending crafted API requests.

CVE-2025-21987
Linux DevOps Web
N/A
UNKNOWN
EPSS
0.0%
2025 1 PoC

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: init return value in amdgpu_ttm_clear_buffer Otherwise an uninitialized value can be returned if amdgpu_res_cleared returns true for all regions. Possibly closes: https://gitlab.freedesktop.org/drm/amd/-/issues/3812 (cherry picked from commit 7c62aacc3b452f73a1284198c81551035fac6d71)