CVE-2018-18645: Infoleak
An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows for Information Exposure via unsubscribe links in email replies.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-18645?
CVE-2018-18645 is classified as a medium severity vulnerability due to information exposure risks.
How do I fix CVE-2018-18645?
To fix CVE-2018-18645, update your GitLab installation to version 11.2.7, 11.3.8, or 11.4.3 or later.
What versions of GitLab are affected by CVE-2018-18645?
CVE-2018-18645 affects GitLab Community and Enterprise Editions before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3.
What type of vulnerability is CVE-2018-18645?
CVE-2018-18645 is an information exposure vulnerability that can leak sensitive data through unsubscribe links in email replies.
Is CVE-2018-18645 a critical vulnerability?
CVE-2018-18645 is not considered critical but poses risks that should be addressed with timely updates.