CVE-2018-14604: XSS
Published Jul 27, 2018
·Updated
An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. XSS can occur in the tooltip of the job inside the CI/CD pipeline.
Affected Software
6 affected components
GitLab GitLab<10.8.7
GitLab GitLab<10.8.7
GitLab GitLab>=11.0.0<11.0.5
GitLab GitLab>=11.0.0<11.0.5
GitLab GitLab>=11.1.0<11.1.2
GitLab GitLab>=11.1.0<11.1.2
Event History
Jul 27, 2018
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-14604?
CVE-2018-14604 is classified as a medium severity vulnerability due to its potential for XSS attacks.
2
How do I fix CVE-2018-14604?
To fix CVE-2018-14604, upgrade GitLab to version 10.8.7, 11.0.5, or 11.1.2 or later.
3
What versions of GitLab are affected by CVE-2018-14604?
CVE-2018-14604 affects GitLab Community and Enterprise Editions before versions 10.8.7, 11.0.5, and 11.1.2.
4
What kind of vulnerability is CVE-2018-14604?
CVE-2018-14604 is a Cross-Site Scripting (XSS) vulnerability that can occur in the CI/CD pipeline tooltips.
5
Can CVE-2018-14604 be exploited in production environments?
Yes, if not patched, CVE-2018-14604 can be exploited in production environments to execute malicious scripts.