First published: Tue Dec 04 2018(Updated: )
An issue was discovered in GitLab Community Edition 11.x before 11.1.8, 11.2.x before 11.2.5, and 11.3.x before 11.3.2. There is Information Exposure via Epic change descriptions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=11.0.0<11.1.8 | |
GitLab | >=11.2.0<11.2.5 | |
GitLab | >=11.3.0<11.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-17976 has been classified as having a medium severity level due to the risk of information exposure.
To fix CVE-2018-17976, upgrade your GitLab Community Edition to version 11.1.8, 11.2.5, or 11.3.2 or later.
CVE-2018-17976 affects GitLab Community Edition versions prior to 11.1.8, 11.2.5, and 11.3.2.
CVE-2018-17976 allows unauthorized users to view content in Epic change descriptions.
CVE-2018-17976 was publicly disclosed on October 5, 2018.