SB2018071813 - Path traversal in GitLab, Gitlab Community Edition
Published: July 18, 2018 Updated: July 17, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Path traversal (CVE-ID: CVE-2018-14364)
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
GitLab Community and Enterprise Edition before 10.7.7, 10.8.x before 10.8.6, and 11.x before 11.0.4 allows Directory Traversal with write access and resultant remote code execution via the GitLab projects import component.
Remediation
Install update from vendor's website.