CVE-2018-16048: Medium severity gitlab vulnerability
Published Oct 3, 2018
·Updated
An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Missing Authorization Control for API Repository Storage.
Affected Software
3 affected components
GitLab GitLab>=8.10.0<11.0.6
GitLab GitLab>=11.1.0<11.1.5
GitLab GitLab>=11.2.0<11.2.2
Event History
Oct 3, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-16048?
CVE-2018-16048 has a moderate severity level due to missing authorization controls for API repository storage.
2
How do I fix CVE-2018-16048?
To fix CVE-2018-16048, upgrade your GitLab installation to version 11.0.6, 11.1.5, or 11.2.2 or later.
3
What versions of GitLab are affected by CVE-2018-16048?
CVE-2018-16048 affects GitLab Community and Enterprise Editions before versions 11.0.6, 11.1.5, and 11.2.2.
4
What type of vulnerability is CVE-2018-16048?
CVE-2018-16048 is categorized as an authorization vulnerability affecting API repository access.
5
What can happen if CVE-2018-16048 is exploited?
Exploitation of CVE-2018-16048 could lead to unauthorized access to repository storage via the API.