CVE-2018-19493
Last modified
CVE-2018-19493 is a vulnerability of currently unknown severity. An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is a persistent XSS vulnerability in the environment pages due to a lack of input validation and output encoding.. EPSS estimates a 1.30% chance of exploitation in the next 30 days.
Description
An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is a persistent XSS vulnerability in the environment pages due to a lack of input validation and output encoding.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gitlab | Gitlab | >= 11.0.0, < 11.3.11 |
| Gitlab | Gitlab | >= 11.4.0, < 11.4.8 |
| Gitlab | Gitlab | >= 11.5.0, < 11.5.1 |
References
- http://www.securityfocus.com/bid/109122Third Party Advisory, VDB Entry
- https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/Release Notes, Vendor Advisory
- https://gitlab.com/gitlab-org/gitlab-ce/issues/53037Issue Tracking, Vendor Advisory
- http://www.securityfocus.com/bid/109122Third Party Advisory, VDB Entry
- https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/Release Notes, Vendor Advisory
- https://gitlab.com/gitlab-org/gitlab-ce/issues/53037Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-19493?
How severe is CVE-2018-19493?
How do I fix CVE-2018-19493?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-19488The WP-jobhunt plugin before version 2.4 for WordPress does …
- CVE-2018-19489v9fs_wstat in hw/9pfs/9p.c in QEMU allows guest OS users to …4.7
- CVE-2018-1949IBM Security Identity Governance and Intelligence 5.2 throug…4.3
- CVE-2018-19490An issue was discovered in datafile.c in Gnuplot 5.2.5. This…
- CVE-2018-19491An issue was discovered in post.trm in Gnuplot 5.2.5. This i…
- CVE-2018-19492An issue was discovered in cairo.trm in Gnuplot 5.2.5. This …
- CVE-2018-19494An issue was discovered in GitLab Community and Enterprise E…
- CVE-2018-19495An issue was discovered in GitLab Community and Enterprise E…
- CVE-2018-19496An issue was discovered in GitLab Community and Enterprise E…
- CVE-2018-19497In The Sleuth Kit (TSK) through 4.6.4, hfs_cat_traverse in t…6.5
- CVE-2018-19498The Simplenia Pages plugin 2.6.0 for Atlassian Bitbucket Ser…
- CVE-2018-19499Vanilla before 2.5.5 and 2.6.x before 2.6.2 allows Remote Co…
Are you affected by CVE-2018-19493?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
