First published: Fri Jul 27 2018(Updated: )
An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. Information Disclosure can occur because the Prometheus metrics feature discloses private project pathnames.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | <10.8.7 | |
GitLab | <10.8.7 | |
GitLab | >=11.0.0<11.0.5 | |
GitLab | >=11.0.0<11.0.5 | |
GitLab | >=11.1.0<11.1.2 | |
GitLab | >=11.1.0<11.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-14602 has a medium severity due to its potential to disclose private project pathnames.
To fix CVE-2018-14602, upgrade to GitLab Community or Enterprise Edition version 10.8.7, 11.0.5, or 11.1.2 or later.
CVE-2018-14602 is an Information Disclosure vulnerability affecting certain versions of GitLab.
CVE-2018-14602 affects GitLab versions before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2.
The Prometheus metrics feature in GitLab is responsible for the information disclosure in CVE-2018-14602.