CVE-2018-19581: High severity gitlab vulnerability
Published Jul 10, 2019
·Updated
GitLab EE, versions 8.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure object reference vulnerability that allows a Guest user to set the weight of an issue they create.
Affected Software
3 affected components
GitLab GitLab>=8.3.0<11.3.11
GitLab GitLab>=11.4.0<11.4.8
GitLab GitLab>=11.5.0<11.5.1
Event History
Jul 10, 2019
CVE Published
via MITRE·04:48 PM
Data Sourced
via MITRE·04:48 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-19581?
CVE-2018-19581 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2018-19581?
To fix CVE-2018-19581, upgrade GitLab EE to version 11.3.11, 11.4.8, or 11.5.1 or later.
3
Who is affected by CVE-2018-19581?
CVE-2018-19581 affects GitLab EE versions from 8.3 up to 11.x before the specified fixed versions.
4
What type of vulnerability is CVE-2018-19581?
CVE-2018-19581 is an insecure object reference vulnerability allowing unauthorized actions by Guest users.
5
What can an attacker do with CVE-2018-19581?
An attacker can exploit CVE-2018-19581 to set the weight of issues they create, manipulating issue management.