CVE-2018-18643: XSS
Published Apr 25, 2019
·Updated
GitLab CE & EE 11.2 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 have Persistent XSS.
Affected Software
32 affected components
GitLab GitLab<=11.2.0
GitLab GitLab<=11.2.0
GitLab GitLab>=11.3.0<11.3.10
GitLab GitLab>=11.3.0<11.3.10
GitLab GitLab>=11.4.0<11.4.6
GitLab GitLab>=11.4.0<11.4.6
GitLab GitLab>=11.4.7<=11.4.9
GitLab GitLab>=11.4.7<=11.4.9
GitLab GitLab=11.5.0
GitLab GitLab=11.5.0
GitLab GitLab=11.5.0-rc1
GitLab GitLab=11.5.0-rc1
GitLab GitLab=11.5.0-rc10
GitLab GitLab=11.5.0-rc10
GitLab GitLab=11.5.0-rc11
GitLab GitLab=11.5.0-rc11
GitLab GitLab=11.5.0-rc2
GitLab GitLab=11.5.0-rc2
GitLab GitLab=11.5.0-rc3
GitLab GitLab=11.5.0-rc3
GitLab GitLab=11.5.0-rc4
GitLab GitLab=11.5.0-rc4
GitLab GitLab=11.5.0-rc5
GitLab GitLab=11.5.0-rc5
GitLab GitLab=11.5.0-rc6
GitLab GitLab=11.5.0-rc6
GitLab GitLab=11.5.0-rc7
GitLab GitLab=11.5.0-rc7
GitLab GitLab=11.5.0-rc8
GitLab GitLab=11.5.0-rc8
GitLab GitLab=11.5.0-rc9
GitLab GitLab=11.5.0-rc9
Remediation
Patch Available
Event History
Apr 25, 2019
CVE Published
via MITRE·08:17 PM
Data Sourced
via MITRE·08:17 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-18643?
CVE-2018-18643 is classified as a high severity vulnerability due to the presence of persistent cross-site scripting (XSS).
2
How do I fix CVE-2018-18643?
To fix CVE-2018-18643, update your GitLab instance to versions 11.4.6 or later if you are running GitLab Community Edition or Enterprise Edition.
3
Which GitLab versions are affected by CVE-2018-18643?
CVE-2018-18643 affects GitLab versions 11.2.0 through 11.4.5 and all versions between 11.3.0 and 11.3.10.
4
What type of vulnerability is CVE-2018-18643?
CVE-2018-18643 is a persistent cross-site scripting (XSS) vulnerability.
5
Is CVE-2018-18643 applicable to both GitLab CE and EE?
Yes, CVE-2018-18643 affects both GitLab Community Edition (CE) and Enterprise Edition (EE).