CVE-2018-20496: XSS
Published Dec 30, 2019
·Updated
An issue was discovered in GitLab Community and Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows XSS.
Affected Software
6 affected components
GitLab GitLab>=8.10.0<11.4.13
GitLab GitLab>=8.10.0<11.4.13
GitLab GitLab>=11.5.0<11.5.6
GitLab GitLab>=11.5.0<11.5.6
GitLab GitLab>=11.6.0<11.6.1
GitLab GitLab>=11.6.0<11.6.1
Event History
Dec 30, 2019
CVE Published
via MITRE·09:24 PM
Data Sourced
via MITRE·09:24 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20496?
CVE-2018-20496 is classified as a medium severity vulnerability due to its potential for XSS attacks.
2
How do I fix CVE-2018-20496?
To fix CVE-2018-20496, upgrade GitLab to version 11.4.13, 11.5.6, or 11.6.1 or later.
3
What types of systems are affected by CVE-2018-20496?
CVE-2018-20496 affects GitLab Community and Enterprise Editions version 11.2.x through 11.4.x, 11.5.x before 11.5.6, and 11.6.x before 11.6.1.
4
What is the nature of the vulnerability CVE-2018-20496?
CVE-2018-20496 allows for cross-site scripting (XSS) attacks on vulnerable GitLab installations.
5
Who is impacted by CVE-2018-20496?
Users and administrators of GitLab versions affected by CVE-2018-20496 are at risk of XSS vulnerabilities.