CVE-2018-17976: Infoleak
Published Dec 4, 2018
·Updated
An issue was discovered in GitLab Community Edition 11.x before 11.1.8, 11.2.x before 11.2.5, and 11.3.x before 11.3.2. There is Information Exposure via Epic change descriptions.
Affected Software
3 affected components
GitLab GitLab>=11.0.0<11.1.8
GitLab GitLab>=11.2.0<11.2.5
GitLab GitLab>=11.3.0<11.3.2
Event History
Dec 4, 2018
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-17976?
CVE-2018-17976 has been classified as having a medium severity level due to the risk of information exposure.
2
How do I fix CVE-2018-17976?
To fix CVE-2018-17976, upgrade your GitLab Community Edition to version 11.1.8, 11.2.5, or 11.3.2 or later.
3
What types of systems are affected by CVE-2018-17976?
CVE-2018-17976 affects GitLab Community Edition versions prior to 11.1.8, 11.2.5, and 11.3.2.
4
What information is exposed due to CVE-2018-17976?
CVE-2018-17976 allows unauthorized users to view content in Epic change descriptions.
5
When was CVE-2018-17976 publicly disclosed?
CVE-2018-17976 was publicly disclosed on October 5, 2018.