CVE-2018-12607: XSS
Published Aug 3, 2018
·Updated
An issue was discovered in GitLab Community Edition and Enterprise Edition before 10.7.6, 10.8.x before 10.8.5, and 11.x before 11.0.1. The charts feature contained a persistent XSS issue due to a lack of output encoding.
Affected Software
6 affected components
GitLab GitLab<10.7.6
GitLab GitLab<10.7.6
GitLab GitLab>=10.8.0<10.8.5
GitLab GitLab>=10.8.0<10.8.5
GitLab GitLab>=11.0.0<11.0.1
GitLab GitLab>=11.0.0<11.0.1
Remediation
Patch Available
Event History
Aug 3, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-12607?
CVE-2018-12607 has a medium severity rating due to its persistent XSS vulnerability.
2
How do I fix CVE-2018-12607?
To fix CVE-2018-12607, upgrade GitLab to version 10.7.6, 10.8.5, or 11.0.1 or later.
3
Which versions of GitLab are affected by CVE-2018-12607?
CVE-2018-12607 affects GitLab Community Edition and Enterprise Edition versions before 10.7.6, 10.8.x before 10.8.5, and 11.x before 11.0.1.
4
What type of vulnerability is CVE-2018-12607?
CVE-2018-12607 is a persistent cross-site scripting (XSS) vulnerability.
5
Is there a workaround for CVE-2018-12607?
There are no published workarounds for CVE-2018-12607; upgrading to a fixed version is the recommended action.