MEDIUM
CVE-2018-19583
CVSS
6.5
Description
GitLab CE/EE, versions 8.0 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, would log access tokens in the Workhorse logs, permitting administrators with access to the logs to see another user's token.
Summary dbcve.org
GitLab Workhorse component logs access tokens in plaintext to log files. Any administrator with access to these logs can view other users' tokens, potentially allowing token theft and unauthorized access.
Mitigation
Upgrade GitLab to version 11.3.11, 11.4.8, 11.5.1 or later. Alternatively, restrict administrative access to Workhorse log files until patching is possible.
Weakness (CWE)
CWE-532
Sensitive Information in Logs
EPSS Score
1.64%
Probability of exploitation in next 30 days
75.4th percentile
References
http://www.securityfocus.com/bid/109166
Broken Link, Third Party Advisory, VDB Entry
https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/
Broken Link, Release Notes, Vendor Advisory
https://gitlab.com/gitlab-org/gitlab-workhorse/issues/182
Issue Tracking, Vendor Advisory
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.