CVE-2018-20494: High severity gitlab vulnerability
Published Dec 30, 2019
·Updated
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.
Affected Software
6 affected components
GitLab GitLab>=8.4.0<11.4.13
GitLab GitLab>=8.4.0<11.4.13
GitLab GitLab>=11.5.0<11.5.6
GitLab GitLab>=11.5.0<11.5.6
GitLab GitLab>=11.6.0<11.6.1
GitLab GitLab>=11.6.0<11.6.1
Remediation
Patch Available
Event History
Dec 30, 2019
CVE Published
via MITRE·09:24 PM
Data Sourced
via MITRE·09:24 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20494?
CVE-2018-20494 is classified as a high severity vulnerability due to issues with incorrect access control.
2
How do I fix CVE-2018-20494?
To fix CVE-2018-20494, update GitLab to version 11.4.13, 11.5.6, or 11.6.1 or later.
3
What versions are affected by CVE-2018-20494?
CVE-2018-20494 affects GitLab Community and Enterprise Editions prior to versions 11.4.13, 11.5.6, and 11.6.1.
4
What impact does CVE-2018-20494 have?
CVE-2018-20494 allows unauthorized access to certain features in GitLab, potentially exposing sensitive data.
5
Who should be concerned about CVE-2018-20494?
Organizations using affected versions of GitLab should prioritize patching CVE-2018-20494 to secure their systems.