First published: Sat Apr 15 2023(Updated: )
An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Side Request Forgery (SSRF) via the Kubernetes integration, leading (for example) to disclosure of a GCP service token.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | <11.1.7 | |
GitLab | <11.1.7 | |
GitLab | >=11.2.0<11.2.4 | |
GitLab | >=11.2.0<11.2.4 | |
GitLab | =11.3.0 | |
GitLab | =11.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-17450 has been classified as a medium severity vulnerability.
To fix CVE-2018-17450, upgrade GitLab to version 11.1.7, 11.2.4, or 11.3.1 or later.
CVE-2018-17450 is identified as a Server-Side Request Forgery (SSRF) vulnerability.
Due to CVE-2018-17450, there is potential disclosure of a Google Cloud Platform (GCP) service token.
GitLab Community and Enterprise Editions before 11.1.7, between 11.2.0 and 11.2.4, and 11.3.0 are affected by CVE-2018-17450.