CVE-2018-18843: SSRF
Published Dec 4, 2018
·Updated
The Kubernetes integration in GitLab Enterprise Edition 11.x before 11.2.8, 11.3.x before 11.3.9, and 11.4.x before 11.4.4 has SSRF.
Affected Software
3 affected components
GitLab GitLab>=11.0.0<11.2.8
GitLab GitLab>=11.3.0<11.3.9
GitLab GitLab>=11.4.0<11.4.4
Remediation
Patch Available
Event History
Dec 4, 2018
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-18843?
CVE-2018-18843 is classified as a critical severity vulnerability due to its potential for SSRF exploitation.
2
How do I fix CVE-2018-18843?
To fix CVE-2018-18843, upgrade GitLab Enterprise Edition to version 11.2.8, 11.3.9, or 11.4.4 or later.
3
What types of systems are affected by CVE-2018-18843?
CVE-2018-18843 affects GitLab Enterprise Edition versions prior to 11.2.8, 11.3.9, and 11.4.4.
4
What impact does CVE-2018-18843 have on my environment?
CVE-2018-18843 allows attackers to potentially exploit server-side request forgery vulnerabilities, leading to unauthorized access to internal services.
5
Is there any mitigation for CVE-2018-18843 aside from upgrading?
There are no effective mitigations for CVE-2018-18843 other than upgrading to a patched version of GitLab.