First published: Fri May 17 2019(Updated: )
GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1 have CRLF Injection in Project Mirroring when using the Git protocol.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=8.18.0<11.3.11 | |
GitLab | >=8.18.0<11.3.11 | |
GitLab | >=11.4.0<11.4.8 | |
GitLab | >=11.4.0<11.4.8 | |
GitLab | >=11.5.0<11.5.1 | |
GitLab | >=11.5.0<11.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-19585 is considered to be high due to its impact on project mirroring through CRLF injection.
To fix CVE-2018-19585, upgrade GitLab to version 11.3.11 or higher for 11.x, or to versions 11.4.8 and 11.5.1 as applicable.
GitLab community and enterprise editions from version 8.18 up to 11.3.10, as well as 11.4.x before 11.4.8, and 11.5.x before 11.5.1 are affected by CVE-2018-19585.
CVE-2018-19585 is a CRLF injection vulnerability that affects the Git protocol in GitLab project mirroring.
If exploited, CVE-2018-19585 could allow attackers to inject HTTP response headers, potentially resulting in security issues such as information disclosure.