Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

GitLab, Atlassian Patch High-Severity Vulnerabilities

Posted on May 22, 2025May 22, 2025 By CWS

GitLab and Atlassian this week introduced the discharge of patches for over a dozen vulnerabilities throughout their product portfolios, together with a number of high-severity bugs.

On Tuesday, Atlassian printed eight advisories detailing six high-severity flaws in Bamboo, Confluence, Fisheye/Crucible, and Jira.

All safety defects have been recognized in third-party dependencies utilized by these merchandise. Their exploitation might enable attackers to trigger denial of service (DoS) situations or elevate their privileges on a weak system.

“To repair all of the vulnerabilities impacting your product(s), Atlassian recommends patching your situations to the newest model,” the corporate notes.

On Wednesday, GitLab introduced fixes for 10 bugs affecting GitLab Group Version (CE) and Enterprise Version (EE).

An important of those flaws is CVE-2025-0993, a high-severity concern that could possibly be exploited by authenticated attackers to trigger a DoS situation by exhausting server sources.

GitLab additionally introduced patches for seven medium-severity flaws that could possibly be exploited to bypass two-factor authentication, trigger a DoS situation, reveal masked or hidden CI variables within the WebUI, or view full electronic mail addresses that must be partially hidden.

Two low-severity vulnerabilities that might result in department identify confusion and unauthorized entry to Job Knowledge have been additionally resolved.Commercial. Scroll to proceed studying.

Patches for all these safety defects have been included in GitLab CE/EE variations 17.10.7, 17.11.3, and 18.0.1. Customers are suggested to replace their installations as quickly as doable.

Neither Atlassian, nor GitLab point out any of those vulnerabilities being exploited in assaults.

Associated: Chrome 136 Replace Patches Vulnerability With ‘Exploit within the Wild’

Associated: Fortinet Patches Zero-Day Exploited In opposition to FortiVoice Home equipment

Associated: Ivanti Patches Two EPMM Zero-Days Exploited to Hack Prospects

Associated: SAP Patches One other Exploited NetWeaver Vulnerability

Security Week News Tags:Atlassian, GitLab, HighSeverity, Patch, Vulnerabilities

Post navigation

Previous Post: How to Secure Your Home Wi-Fi Network
Next Post: FBI and Europol Disrupt Lumma Stealer Malware Network Linked to 10 Million Infections

Related Posts

Iranian Man Pleads Guilty to Role in Baltimore Ransomware Attack Security Week News
Hawaiian Airlines Hacked as Aviation Sector Warned of Scattered Spider Attacks Security Week News
New AI Jailbreak Bypasses Guardrails With Ease Security Week News
Russian Government Hackers Caught Buying Passwords from Cybercriminals Security Week News
Critical Vulnerability Patched in Citrix NetScaler Security Week News
Cellcom Service Disruption Caused by Cyberattack Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • How to Identify Fake Mobile Apps
  • “CitrixBleed 2” Vulnerability PoC Released
  • Russia Jailed Hacker Who Worked for Ukrainian Intelligence to Launch Cyberattacks on Critical Infrastructure
  • Threat Actors Turning Job Offers Into Traps, Over $264 Million Lost in 2024 Alone
  • Instagram Started Using 1-Week Validity TLS certificates and Changes Them Daily

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • How to Identify Fake Mobile Apps
  • “CitrixBleed 2” Vulnerability PoC Released
  • Russia Jailed Hacker Who Worked for Ukrainian Intelligence to Launch Cyberattacks on Critical Infrastructure
  • Threat Actors Turning Job Offers Into Traps, Over $264 Million Lost in 2024 Alone
  • Instagram Started Using 1-Week Validity TLS certificates and Changes Them Daily

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News