CVE-2018-17451: CSRF
An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Cross Site Request Forgery (CSRF) in the Slack integration for issuing slash commands.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-17451?
CVE-2018-17451 is classified as a medium severity vulnerability due to its Cross Site Request Forgery (CSRF) risk in Slack integration.
How do I fix CVE-2018-17451?
To fix CVE-2018-17451, upgrade GitLab to version 11.1.7, 11.2.4, or 11.3.1 or later.
What versions of GitLab are affected by CVE-2018-17451?
CVE-2018-17451 affects GitLab Community and Enterprise Editions prior to versions 11.1.7, 11.2.4, and 11.3.1.
What type of vulnerability is CVE-2018-17451?
CVE-2018-17451 is a Cross Site Request Forgery (CSRF) vulnerability impacting the Slack integration.
Is the Slack integration the only affected feature in CVE-2018-17451?
Yes, the vulnerability specifically affects the Slack integration for issuing slash commands within GitLab.