VulnerabilityModified
CVE-2018-14364
GitLab Community and Enterprise Edition before 10.7.7, 10.8.x before 10.8.6, and 11.x before 11.0.4 allows Directory Traversal with write access and resultant remote code execution via the GitLab projects import component.
CRITICAL 9.8EPSS 50.1%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 50.1%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
GitLab Community and Enterprise Edition before 10.7.7, 10.8.x before 10.8.6, and 11.x before 11.0.4 allows Directory Traversal with write access and resultant remote code execution via the GitLab projects import component.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 50.08% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- gitlab/gitlab
- Source
- cve@mitre.org
References
- https://about.gitlab.com/2018/07/17/critical-security-release-gitlab-11-dot-0-dot-4-released/Vendor Advisory
- https://gitlab.com/gitlab-org/gitlab-ce/issues/49133Exploit, Vendor Advisory
- https://hackerone.com/reports/378148Exploit, Third Party Advisory
- https://about.gitlab.com/2018/07/17/critical-security-release-gitlab-11-dot-0-dot-4-released/Vendor Advisory
- https://gitlab.com/gitlab-org/gitlab-ce/issues/49133Exploit, Vendor Advisory
- https://hackerone.com/reports/378148Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.