First published: Thu Apr 25 2019(Updated: )
GitLab Community and Enterprise Edition 8.9 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 has Incorrect Access Control.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=11.3.0<11.3.10 | |
GitLab | >=11.3.0<11.3.10 | |
GitLab | >=11.4.0<11.4.6 | |
GitLab | >=11.4.0<11.4.6 | |
GitLab | >=11.4.7<=11.4.9 | |
GitLab | >=11.4.7<=11.4.9 | |
GitLab | =11.5.0 | |
GitLab | =11.5.0 | |
GitLab | =11.5.0-rc1 | |
GitLab | =11.5.0-rc1 | |
GitLab | =11.5.0-rc10 | |
GitLab | =11.5.0-rc10 | |
GitLab | =11.5.0-rc11 | |
GitLab | =11.5.0-rc11 | |
GitLab | =11.5.0-rc2 | |
GitLab | =11.5.0-rc2 | |
GitLab | =11.5.0-rc3 | |
GitLab | =11.5.0-rc3 | |
GitLab | =11.5.0-rc4 | |
GitLab | =11.5.0-rc4 | |
GitLab | =11.5.0-rc5 | |
GitLab | =11.5.0-rc5 | |
GitLab | =11.5.0-rc6 | |
GitLab | =11.5.0-rc6 | |
GitLab | =11.5.0-rc7 | |
GitLab | =11.5.0-rc7 | |
GitLab | =11.5.0-rc8 | |
GitLab | =11.5.0-rc8 | |
GitLab | =11.5.0-rc9 | |
GitLab | =11.5.0-rc9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19359 is rated as a critical vulnerability due to incorrect access control in GitLab.
To mitigate CVE-2018-19359, upgrade GitLab to version 11.5.0 or later or apply the available patches provided in the security release.
CVE-2018-19359 affects GitLab Community and Enterprise editions from version 8.9 up to but not including 11.5.0-rc12.
CVE-2018-19359 is classified as an access control vulnerability that allows unauthorized actions.
No, CVE-2018-19359 is no longer exploitable in GitLab versions released after 11.5.0.