An issue has been discovered in GitLab EE/CE that could allow an attacker to track users' browsing activities, potentially leading to full account take-over, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.
2025-04-24T08:15:14.333
2025-08-08T16:54:22.630
Analyzed
CVSSv3.1: 7.7 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | gitlab | gitlab | < 17.9.7 | Yes |
| Application | gitlab | gitlab | < 17.9.7 | Yes |
| Application | gitlab | gitlab | < 17.10.5 | Yes |
| Application | gitlab | gitlab | < 17.10.5 | Yes |
| Application | gitlab | gitlab | 17.11.0 | Yes |
| Application | gitlab | gitlab | 17.11.0 | Yes |