{"id":"CGA-949p-5cv3-ggfg","modified":"2026-01-28T03:23:37.453466Z","published":"2025-03-31T16:02:59.786179Z","withdrawn":"2026-01-28T03:23:37.453466Z","related":["CGA-949p-5cv3-ggfg","CVE-2025-22870","GHSA-qxp5-gwg8-xv66"],"affected":[{"package":{"name":"gitlab-cng-17.9","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/gitlab-cng-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-cng-17.9","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/gitlab-cng-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitaly-config-17.9","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/gitaly-config-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitaly-config-17.9","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/gitaly-config-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-base-17.9","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/gitlab-base-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-base-17.9","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/gitlab-base-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-certificates-17.9","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/gitlab-certificates-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-certificates-17.9","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/gitlab-certificates-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-cfssl-self-sign-scripts-17.9","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/gitlab-cfssl-self-sign-scripts-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-cfssl-self-sign-scripts-17.9","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/gitlab-cfssl-self-sign-scripts-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-container-registry-17.9","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/gitlab-container-registry-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-container-registry-17.9","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/gitlab-container-registry-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-container-registry-scripts-17.9","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/gitlab-container-registry-scripts-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-container-registry-scripts-17.9","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/gitlab-container-registry-scripts-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-elasticsearch-indexer-17.9","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/gitlab-elasticsearch-indexer-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-elasticsearch-indexer-17.9","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/gitlab-elasticsearch-indexer-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-elasticsearch-indexer-compat-17.9","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/gitlab-elasticsearch-indexer-compat-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-elasticsearch-indexer-compat-17.9","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/gitlab-elasticsearch-indexer-compat-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-exporter-17.9","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/gitlab-exporter-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-exporter-17.9","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/gitlab-exporter-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-exporter-scripts-17.9","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/gitlab-exporter-scripts-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-exporter-scripts-17.9","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/gitlab-exporter-scripts-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-geo-logcursor-scripts-17.9","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/gitlab-geo-logcursor-scripts-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-geo-logcursor-scripts-17.9","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/gitlab-geo-logcursor-scripts-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-gitaly-scripts-17.9","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/gitlab-gitaly-scripts-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-gitaly-scripts-17.9","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/gitlab-gitaly-scripts-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-logger-17.9","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/gitlab-logger-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-logger-17.9","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/gitlab-logger-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-logger-compat-17.9","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/gitlab-logger-compat-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-logger-compat-17.9","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/gitlab-logger-compat-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-mailroom-17.9","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/gitlab-mailroom-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-mailroom-17.9","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/gitlab-mailroom-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-mailroom-scripts-17.9","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/gitlab-mailroom-scripts-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-mailroom-scripts-17.9","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/gitlab-mailroom-scripts-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-pages-scripts-17.9","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/gitlab-pages-scripts-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-pages-scripts-17.9","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/gitlab-pages-scripts-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-rails-scripts-17.9","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/gitlab-rails-scripts-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-rails-scripts-17.9","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/gitlab-rails-scripts-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-shell-17.9","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/gitlab-shell-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-shell-17.9","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/gitlab-shell-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-shell-scripts-17.9","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/gitlab-shell-scripts-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-shell-scripts-17.9","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/gitlab-shell-scripts-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-shell-scripts-compat-17.9","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/gitlab-shell-scripts-compat-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-shell-scripts-compat-17.9","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/gitlab-shell-scripts-compat-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-sidekiq-scripts-17.9","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/gitlab-sidekiq-scripts-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-sidekiq-scripts-17.9","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/gitlab-sidekiq-scripts-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-toolbox-scripts-17.9","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/gitlab-toolbox-scripts-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-toolbox-scripts-17.9","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/gitlab-toolbox-scripts-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-webservice-config-17.9","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/gitlab-webservice-config-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-webservice-config-17.9","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/gitlab-webservice-config-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-webservice-scripts-17.9","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/gitlab-webservice-scripts-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-webservice-scripts-17.9","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/gitlab-webservice-scripts-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-workhorse-scripts-17.9","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/gitlab-workhorse-scripts-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}},{"package":{"name":"gitlab-workhorse-scripts-17.9","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/gitlab-workhorse-scripts-17.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.9.2-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-949p-5cv3-ggfg.json"}}],"schema_version":"1.7.3"}