CVE-2025-12575
Gravedad CVSS v3.1:
MEDIA
Tipo:
CWE-918
Falsificación de solicitud en servidor (SSRF)
Fecha de publicación:
11/02/2026
Última modificación:
11/02/2026
Descripción
*** Pendiente de traducción *** GitLab has remediated an issue in GitLab EE affecting all versions from 18.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user with certain permissions to make unauthorized requests to internal network services through the GitLab server.
Impacto
Puntuación base 3.x
5.40
Gravedad 3.x
MEDIA



