CVE-2018-14602
Summary
| CVE | CVE-2018-14602 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-07-27 02:29:00 UTC |
| Updated | 2018-09-18 18:25:00 UTC |
| Description | An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. Information Disclosure can occur because the Prometheus metrics feature discloses private project pathnames. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| GitLab Security Release: 11.1.2, 11.0.5, and 10.8.7 | GitLab | MISC | about.gitlab.com | Release Notes, Vendor Advisory |
| monitor.gitlab.net exposes private information (#4423) · Issues · GitLab.com / GitLab Infrastructure Team / infrastructure · GitLab | CONFIRM | gitlab.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 690576 Free Berkeley Software Distribution (FreeBSD) Security Update for gitlab (2da838f9-9168-11e8-8c75-d8cb8abf62dd)