#VU107882 Improper Neutralization of HTTP Headers for Scripting Syntax in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2025-1908
Published: April 23, 2025
GitLab Enterprise Edition
Gitlab Community Edition
GitLab, Inc
Description
The vulnerability allows a remote user to perform spoofing attack.
The vulnerability exists due to improper input validation when processing Network Error Logging (NEL) HTTP headers in Maven dependency proxy. A remote user can inject a Network Error Logging (NEL) HTTP header into server response and potentially take over an arbitrary account.