First published: Wed Oct 03 2018(Updated: )
An issue was discovered in GitLab Community and Enterprise Edition 11.1.x before 11.1.5 and 11.2.x before 11.2.2. There is Persistent XSS in the Merge Request Changes View.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=10.7.0<=10.7.7 | |
GitLab | >=10.7.0<=10.7.7 | |
GitLab | >=10.8.0<=10.8.6 | |
GitLab | >=10.8.0<=10.8.6 | |
GitLab | >=11.1.0<11.1.5 | |
GitLab | >=11.1.0<11.1.5 | |
GitLab | >=11.2.0<11.2.2 | |
GitLab | >=11.2.0<11.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-16050 has a medium severity rating due to its persistent XSS vulnerability.
To fix CVE-2018-16050, upgrade GitLab to version 11.1.5 or 11.2.2 or later.
CVE-2018-16050 affects GitLab Community and Enterprise Editions from versions 10.7.0 to 11.1.4 and 10.8.0 to 11.2.1.
CVE-2018-16050 is classified as a persistent cross-site scripting (XSS) vulnerability.
Mitigation of CVE-2018-16050 can be achieved by applying the available patches or upgrading to the latest version of GitLab.