HIGH
CVE-2018-14602
CVSS
7.5
Description
An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. Information Disclosure can occur because the Prometheus metrics feature discloses private project pathnames.
Summary dbcve.org
The Prometheus metrics feature in GitLab Community and Enterprise Edition (versions before 10.8.7, 11.0.5, and 11.1.2) incorrectly exposes private project pathnames through its metrics endpoint, allowing unauthenticated attackers to discover internal project directory structures.
Mitigation
Upgrade GitLab to version 10.8.7, 11.0.5, 11.1.2 or later to patch the information disclosure vulnerability in the Prometheus metrics feature.
Weakness (CWE)
CWE-200
Information Exposure
EPSS Score
1.8%
Probability of exploitation in next 30 days
77.4th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.