CRITICAL
CVE-2018-18649
CVSS
9.8
Description
An issue was discovered in the wiki API in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows for remote code execution.
Summary dbcve.org
A vulnerability in the GitLab wiki API allows authenticated attackers to execute arbitrary code remotely on the GitLab server. This critical flaw affects self-hosted GitLab Community and Enterprise Edition installations.
Mitigation
Upgrade GitLab to version 11.2.7, 11.3.8, 11.4.3 or later. If immediate patching is not possible, consider restricting wiki API access via network controls or authentication mechanisms.
EPSS Score
6.74%
Probability of exploitation in next 30 days
93.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.