CVE-2018-17975: Infoleak
Published Dec 4, 2018
·Updated
An issue was discovered in GitLab Community Edition 11.x before 11.1.8, 11.2.x before 11.2.5, and 11.3.x before 11.3.2. There is Information Exposure via the GFM markdown API.
Affected Software
3 affected components
GitLab GitLab>=11.0.0<11.1.8
GitLab GitLab>=11.2.0<11.2.5
GitLab GitLab>=11.3.0<11.3.2
Event History
Dec 4, 2018
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-17975?
CVE-2018-17975 has a medium severity rating due to its potential for information exposure.
2
How do I fix CVE-2018-17975?
To fix CVE-2018-17975, upgrade GitLab Community Edition to version 11.1.8, 11.2.5, or 11.3.2 or later.
3
What versions of GitLab are affected by CVE-2018-17975?
GitLab Community Edition 11.x before 11.1.8, 11.2.x before 11.2.5, and 11.3.x before 11.3.2 are affected by CVE-2018-17975.
4
What type of vulnerability is CVE-2018-17975?
CVE-2018-17975 is classified as an Information Exposure vulnerability via the GFM markdown API.
5
Is CVE-2018-17975 present in GitLab Enterprise Edition?
CVE-2018-17975 specifically affects the GitLab Community Edition and does not pertain to the GitLab Enterprise Edition.