CVE-2018-19856: Path Traversal
Published Mar 26, 2019
·Updated
GitLab CE/EE before 11.3.12, 11.4.x before 11.4.10, and 11.5.x before 11.5.3 allows Directory Traversal in Templates API.
Affected Software
6 affected components
GitLab GitLab<11.3.12
GitLab GitLab<11.3.12
GitLab GitLab>=11.4.0<11.4.10
GitLab GitLab>=11.4.0<11.4.10
GitLab GitLab>=11.5.0<11.5.3
GitLab GitLab>=11.5.0<11.5.3
Event History
Mar 26, 2019
CVE Published
via MITRE·03:50 PM
Data Sourced
via MITRE·03:50 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-19856?
CVE-2018-19856 has a severity rating of medium due to its potential for directory traversal in the Templates API.
2
How do I fix CVE-2018-19856?
To fix CVE-2018-19856, upgrade GitLab to version 11.3.12, 11.4.10, or 11.5.3 or later.
3
Which GitLab versions are affected by CVE-2018-19856?
CVE-2018-19856 affects GitLab CE/EE versions prior to 11.3.12, between 11.4.0 and 11.4.10, and between 11.5.0 and 11.5.3.
4
What type of vulnerability is CVE-2018-19856?
CVE-2018-19856 is a directory traversal vulnerability in the Templates API of GitLab.
5
Is CVE-2018-19856 present in GitLab Community Edition?
Yes, CVE-2018-19856 is present in both GitLab Community Edition and Enterprise Edition prior to the specified versions.