CVE Vulnerabilities

CVE-2018-18641

Cleartext Storage of Sensitive Information

Published: Dec 04, 2018 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has Cleartext Storage of Sensitive Information.

Weakness

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 8.10.0 (including) 11.2.7 (excluding)
Gitlab Gitlab 11.3.0 (including) 11.3.8 (excluding)
Gitlab Gitlab 11.4.0 (including) 11.4.3 (excluding)

Potential Mitigations

References