HIGH

CVE-2018-14602

Gitlab GitLab 2018-07-27 CVSS v3.0
CVSS
7.5

Description

An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. Information Disclosure can occur because the Prometheus metrics feature discloses private project pathnames.

Summary dbcve.org

The Prometheus metrics feature in GitLab Community and Enterprise Edition (versions before 10.8.7, 11.0.5, and 11.1.2) incorrectly exposes private project pathnames through its metrics endpoint, allowing unauthenticated attackers to discover internal project directory structures.

Mitigation

Upgrade GitLab to version 10.8.7, 11.0.5, 11.1.2 or later to patch the information disclosure vulnerability in the Prometheus metrics feature.

Weakness (CWE)

CWE-200 Information Exposure

EPSS Score

1.8%
Probability of exploitation in next 30 days
77.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE