CVE-2018-17453: Medium severity gitlab vulnerability
An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers may have been able to obtain sensitive access-token data from Sentry logs via the GRPC::Unknown exception.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-17453?
CVE-2018-17453 is rated as a moderate severity vulnerability due to the potential exposure of sensitive access-token data.
How do I fix CVE-2018-17453?
To fix CVE-2018-17453, upgrade your GitLab Community or Enterprise Edition to version 11.1.7 or later, or to version 11.2.4 or later.
What versions are affected by CVE-2018-17453?
CVE-2018-17453 affects GitLab Community and Enterprise Editions prior to versions 11.1.7, 11.2.4, and 11.3.1.
What types of data could be compromised by CVE-2018-17453?
CVE-2018-17453 could allow attackers to access sensitive access-token data from Sentry logs.
In which software can I find CVE-2018-17453?
CVE-2018-17453 is found in GitLab Community and Enterprise Editions.