Inclusion of Sensitive Information in Log Files in Gitlab Community Edition - CVE-2018-19583

 

Inclusion of Sensitive Information in Log Files in Gitlab Community Edition - CVE-2018-19583

Published: July 10, 2019 / Updated: July 17, 2020


Vulnerability identifier: #VU30994
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2018-19583
CWE-ID: CWE-532
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: GitLab, Inc
Affected software:
Gitlab Community Edition

Detailed vulnerability description

The vulnerability allows a remote authenticated user to gain access to sensitive information.

GitLab CE/EE, versions 8.0 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, would log access tokens in the Workhorse logs, permitting administrators with access to the logs to see another user's token.


How to mitigate CVE-2018-19583

Install update from vendor's website.

Sources