CVE-2018-18641: Critical severity gitlab vulnerability
Published Dec 4, 2018
·Updated
An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has Cleartext Storage of Sensitive Information.
Affected Software
6 affected components
GitLab GitLab>=8.10.0<11.2.7
GitLab GitLab>=8.10.0<11.2.7
GitLab GitLab>=11.3.0<11.3.8
GitLab GitLab>=11.3.0<11.3.8
GitLab GitLab>=11.4.0<11.4.3
GitLab GitLab>=11.4.0<11.4.3
Event History
Dec 4, 2018
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-18641?
CVE-2018-18641 is considered to have a high severity due to its impact on sensitive information storage.
2
How do I fix CVE-2018-18641?
To mitigate CVE-2018-18641, update GitLab to version 11.2.7, 11.3.8, or 11.4.3 or later.
3
What types of systems are affected by CVE-2018-18641?
CVE-2018-18641 affects both the GitLab Community and Enterprise Editions prior to specified patch versions.
4
What specific data is exposed in CVE-2018-18641?
CVE-2018-18641 details an issue that results in the cleartext storage of sensitive information.
5
Is there a workaround for CVE-2018-18641?
There is no official workaround for CVE-2018-18641; updating to secure versions is essential.