CVE-2018-19572

Severity CVSS v4.0:
Pending analysis
Type:
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Publication date:
10/07/2019
Last modified:
11/07/2019

Description

GitLab CE 8.17 and later and EE 8.3 and later have a symlink time-of-check-to-time-of-use race condition that would allow unauthorized access to files in the GitLab Pages chroot environment. This is fixed in versions 11.5.1, 11.4.8, and 11.3.11.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* 8.3.0 (including) 11.3.11 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* 8.17.0 (including) 11.3.11 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* 11.3.12 (including) 11.4.8 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* 11.3.12 (including) 11.4.8 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* 11.4.9 (including) 11.5.1 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* 11.4.9 (including) 11.5.1 (excluding)