CVE-2018-20491: XSS
An issue was discovered in GitLab Enterprise Edition 11.3.x and 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows XSS.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-20491?
CVE-2018-20491 is classified as a medium severity vulnerability due to its potential impact through cross-site scripting (XSS).
How do I fix CVE-2018-20491?
To fix CVE-2018-20491, upgrade GitLab to version 11.4.13 or later, 11.5.6 or later, or 11.6.1 or later.
What is the impact of CVE-2018-20491?
The impact of CVE-2018-20491 includes the ability for attackers to execute arbitrary JavaScript in the context of a user's session.
Which versions of GitLab are affected by CVE-2018-20491?
CVE-2018-20491 affects GitLab Enterprise Edition versions 11.3.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1.
Is GitLab Community Edition affected by CVE-2018-20491?
Yes, GitLab Community Edition is also affected by CVE-2018-20491 within the same version ranges as the Enterprise Edition.