CVE-2018-19359: High severity gitlab vulnerability
Published Apr 25, 2019
·Updated
GitLab Community and Enterprise Edition 8.9 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 has Incorrect Access Control.
Affected Software
30 affected components
GitLab GitLab>=11.3.0<11.3.10
GitLab GitLab>=11.3.0<11.3.10
GitLab GitLab>=11.4.0<11.4.6
GitLab GitLab>=11.4.0<11.4.6
GitLab GitLab>=11.4.7<=11.4.9
GitLab GitLab>=11.4.7<=11.4.9
GitLab GitLab=11.5.0
GitLab GitLab=11.5.0
GitLab GitLab=11.5.0-rc1
GitLab GitLab=11.5.0-rc1
GitLab GitLab=11.5.0-rc10
GitLab GitLab=11.5.0-rc10
GitLab GitLab=11.5.0-rc11
GitLab GitLab=11.5.0-rc11
GitLab GitLab=11.5.0-rc2
GitLab GitLab=11.5.0-rc2
GitLab GitLab=11.5.0-rc3
GitLab GitLab=11.5.0-rc3
GitLab GitLab=11.5.0-rc4
GitLab GitLab=11.5.0-rc4
GitLab GitLab=11.5.0-rc5
GitLab GitLab=11.5.0-rc5
GitLab GitLab=11.5.0-rc6
GitLab GitLab=11.5.0-rc6
GitLab GitLab=11.5.0-rc7
GitLab GitLab=11.5.0-rc7
GitLab GitLab=11.5.0-rc8
GitLab GitLab=11.5.0-rc8
GitLab GitLab=11.5.0-rc9
GitLab GitLab=11.5.0-rc9
Remediation
Patch Available
Event History
Apr 25, 2019
CVE Published
via MITRE·08:58 PM
Data Sourced
via MITRE·08:58 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-19359?
CVE-2018-19359 is rated as a critical vulnerability due to incorrect access control in GitLab.
2
How do I fix CVE-2018-19359?
To mitigate CVE-2018-19359, upgrade GitLab to version 11.5.0 or later or apply the available patches provided in the security release.
3
Which versions of GitLab are impacted by CVE-2018-19359?
CVE-2018-19359 affects GitLab Community and Enterprise editions from version 8.9 up to but not including 11.5.0-rc12.
4
What type of vulnerability is CVE-2018-19359?
CVE-2018-19359 is classified as an access control vulnerability that allows unauthorized actions.
5
Is CVE-2018-19359 still exploitable in the latest GitLab releases?
No, CVE-2018-19359 is no longer exploitable in GitLab versions released after 11.5.0.