CVE-2018-18644 log
Source |
|
Severity | Medium |
Remote | Yes |
Type | Information disclosure |
Description | A security issue has been found in gitlab versions prior to 11.4.3, where the Prometheus integration was vulnerable to an indirect object reference issue which allowed an unauthorized user to see private information. This information includes the project name, environment name, metric name, and metric query. Additionally, an unauthorized user could create false alarms. |
Group | Package | Affected | Fixed | Severity | Status | Ticket |
---|---|---|---|---|---|---|
AVG-802 | gitlab | 11.4.0-1 | 11.4.3-2 | High | Not affected |
References |
---|
https://about.gitlab.com/2018/10/29/security-release-gitlab-11-dot-4-dot-3-released/ |
Notes |
---|
Only affects Enterprise Edition, not for us. |