CRITICAL

CVE-2018-18649

Gitlab GitLab 2018-11-29 CVSS v3.0
CVSS
9.8

Description

An issue was discovered in the wiki API in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows for remote code execution.

Summary dbcve.org

A vulnerability in the GitLab wiki API allows authenticated attackers to execute arbitrary code remotely on the GitLab server. This critical flaw affects self-hosted GitLab Community and Enterprise Edition installations.

Mitigation

Upgrade GitLab to version 11.2.7, 11.3.8, 11.4.3 or later. If immediate patching is not possible, consider restricting wiki API access via network controls or authentication mechanisms.

EPSS Score

6.74%
Probability of exploitation in next 30 days
93.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE