Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

GitLab, Atlassian Patch High-Severity Vulnerabilities

Posted on May 22, 2025May 22, 2025 By CWS

GitLab and Atlassian this week introduced the discharge of patches for over a dozen vulnerabilities throughout their product portfolios, together with a number of high-severity bugs.

On Tuesday, Atlassian printed eight advisories detailing six high-severity flaws in Bamboo, Confluence, Fisheye/Crucible, and Jira.

All safety defects have been recognized in third-party dependencies utilized by these merchandise. Their exploitation might enable attackers to trigger denial of service (DoS) situations or elevate their privileges on a weak system.

“To repair all of the vulnerabilities impacting your product(s), Atlassian recommends patching your situations to the newest model,” the corporate notes.

On Wednesday, GitLab introduced fixes for 10 bugs affecting GitLab Group Version (CE) and Enterprise Version (EE).

An important of those flaws is CVE-2025-0993, a high-severity concern that could possibly be exploited by authenticated attackers to trigger a DoS situation by exhausting server sources.

GitLab additionally introduced patches for seven medium-severity flaws that could possibly be exploited to bypass two-factor authentication, trigger a DoS situation, reveal masked or hidden CI variables within the WebUI, or view full electronic mail addresses that must be partially hidden.

Two low-severity vulnerabilities that might result in department identify confusion and unauthorized entry to Job Knowledge have been additionally resolved.Commercial. Scroll to proceed studying.

Patches for all these safety defects have been included in GitLab CE/EE variations 17.10.7, 17.11.3, and 18.0.1. Customers are suggested to replace their installations as quickly as doable.

Neither Atlassian, nor GitLab point out any of those vulnerabilities being exploited in assaults.

Associated: Chrome 136 Replace Patches Vulnerability With ‘Exploit within the Wild’

Associated: Fortinet Patches Zero-Day Exploited In opposition to FortiVoice Home equipment

Associated: Ivanti Patches Two EPMM Zero-Days Exploited to Hack Prospects

Associated: SAP Patches One other Exploited NetWeaver Vulnerability

Security Week News Tags:Atlassian, GitLab, HighSeverity, Patch, Vulnerabilities

Post navigation

Previous Post: How to Secure Your Home Wi-Fi Network
Next Post: FBI and Europol Disrupt Lumma Stealer Malware Network Linked to 10 Million Infections

Related Posts

In Other News: $900k for XSS Bugs, HybridPetya Malware, Burger King Censors Research Security Week News
SonicWall Hunts for Zero-Day Amid Surge in Firewall Exploitation Security Week News
Recent Fortra GoAnywhere MFT Vulnerability Exploited as Zero-Day Security Week News
Reach Security Raises $10 Million for Exposure Management Solution Security Week News
CISA: CVE Program to Focus on Vulnerability Data Quality Security Week News
Fortra Patches Critical GoAnywhere MFT Vulnerability Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft Warns of Hackers Abuse Teams Features and Capabilities to Deliver Malware
  • Why Threat Prioritization Is the Key SOC Performance Driver  
  • BK Technologies Data Breach – Hackers Compromise IT Systems and Exfiltrate Data
  • BatShadow Group Uses New Go-Based ‘Vampire Bot’ Malware to Hunt Job Seekers
  • Google’s New AI Doesn’t Just Find Vulnerabilities — It Rewrites Code to Patch Them

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft Warns of Hackers Abuse Teams Features and Capabilities to Deliver Malware
  • Why Threat Prioritization Is the Key SOC Performance Driver  
  • BK Technologies Data Breach – Hackers Compromise IT Systems and Exfiltrate Data
  • BatShadow Group Uses New Go-Based ‘Vampire Bot’ Malware to Hunt Job Seekers
  • Google’s New AI Doesn’t Just Find Vulnerabilities — It Rewrites Code to Patch Them

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News