First published: Tue Mar 26 2019(Updated: )
GitLab CE/EE before 11.3.12, 11.4.x before 11.4.10, and 11.5.x before 11.5.3 allows Directory Traversal in Templates API.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | <11.3.12 | |
GitLab | <11.3.12 | |
GitLab | >=11.4.0<11.4.10 | |
GitLab | >=11.4.0<11.4.10 | |
GitLab | >=11.5.0<11.5.3 | |
GitLab | >=11.5.0<11.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19856 has a severity rating of medium due to its potential for directory traversal in the Templates API.
To fix CVE-2018-19856, upgrade GitLab to version 11.3.12, 11.4.10, or 11.5.3 or later.
CVE-2018-19856 affects GitLab CE/EE versions prior to 11.3.12, between 11.4.0 and 11.4.10, and between 11.5.0 and 11.5.3.
CVE-2018-19856 is a directory traversal vulnerability in the Templates API of GitLab.
Yes, CVE-2018-19856 is present in both GitLab Community Edition and Enterprise Edition prior to the specified versions.