CVE-2018-17939: Infoleak
Published Dec 4, 2018
·Updated
An issue was discovered in GitLab Community and Enterprise Edition 11.1.x before 11.1.8, 11.2.x before 11.2.5, and 11.3.x before 11.3.2. There is Information Exposure via the merge request JSON endpoint.
Affected Software
6 affected components
GitLab GitLab>=11.1.0<11.1.8
GitLab GitLab>=11.1.0<11.1.8
GitLab GitLab>=11.2.0<11.2.5
GitLab GitLab>=11.2.0<11.2.5
GitLab GitLab>=11.3.0<11.3.2
GitLab GitLab>=11.3.0<11.3.2
Event History
Dec 4, 2018
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-17939?
CVE-2018-17939 has a medium severity rating due to the potential for information exposure.
2
How do I fix CVE-2018-17939?
To fix CVE-2018-17939, upgrade GitLab to version 11.1.8, 11.2.5, or 11.3.2 or later.
3
What types of GitLab editions are affected by CVE-2018-17939?
Both GitLab Community and Enterprise Editions are affected by CVE-2018-17939.
4
Which versions of GitLab are vulnerable to CVE-2018-17939?
GitLab versions 11.1.x before 11.1.8, 11.2.x before 11.2.5, and 11.3.x before 11.3.2 are vulnerable to CVE-2018-17939.
5
What kind of information is exposed by CVE-2018-17939?
CVE-2018-17939 allows for information exposure via the merge request JSON endpoint.