CVE-2018-14605: XSS
An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. XSS can occur in the branch name during a Web IDE file commit.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-14605?
CVE-2018-14605 has been classified as a medium severity vulnerability due to its potential for XSS attacks.
How do I fix CVE-2018-14605?
To fix CVE-2018-14605, upgrade your GitLab installation to version 10.8.7, 11.0.5, or 11.1.2 or later.
Who is affected by CVE-2018-14605?
CVE-2018-14605 affects GitLab Community and Enterprise Editions before versions 10.8.7, 11.0.5, and 11.1.2.
What are the implications of exploiting CVE-2018-14605?
Exploiting CVE-2018-14605 may allow an attacker to execute arbitrary scripts in the context of the user's session.
Is there a workaround for CVE-2018-14605 if I can't upgrade?
There are no official workarounds for CVE-2018-14605, so it is strongly advised to apply the necessary updates as soon as possible.