CVE-2018-18649: Critical severity gitlab vulnerability
Published Nov 29, 2018
·Updated
An issue was discovered in the wiki API in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows for remote code execution.
Affected Software
4 affected components
GitLab GitLab>=11.3.0<11.3.8
GitLab GitLab>=11.3.0<11.3.8
GitLab GitLab>=11.4.0<11.4.3
GitLab GitLab>=11.4.0<11.4.3
Event History
Nov 29, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-18649?
CVE-2018-18649 is classified as a critical vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2018-18649?
To fix CVE-2018-18649, upgrade GitLab Community or Enterprise Edition to the latest version beyond 11.2.7, 11.3.8, or 11.4.3.
3
What versions are affected by CVE-2018-18649?
CVE-2018-18649 affects GitLab versions prior to 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3.
4
What type of vulnerability is CVE-2018-18649?
CVE-2018-18649 is a remote code execution vulnerability within the wiki API of GitLab.
5
Can CVE-2018-18649 affect both Community and Enterprise Editions of GitLab?
Yes, CVE-2018-18649 affects both GitLab Community and Enterprise Editions.