Improper Neutralization of HTTP Headers for Scripting Syntax in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2025-1908
Published: April 23, 2025
Vulnerability details
The vulnerability allows a remote user to perform spoofing attack.
The vulnerability exists due to improper input validation when processing Network Error Logging (NEL) HTTP headers in Maven dependency proxy. A remote user can inject a Network Error Logging (NEL) HTTP header into server response and potentially take over an arbitrary account.
Affected software
GitLab Enterprise Edition
How to mitigate CVE-2025-1908
GitLab Enterprise Edition - addressed in versions 17.9.7, 17.10.5, 17.11.1