GitLab CE 8.17 and later and EE 8.3 and later have a symlink time-of-check-to-time-of-use race condition that would allow unauthorized access to files in the GitLab Pages chroot environment. This is fixed in versions 11.5.1, 11.4.8, and 11.3.11.
Advisories
Source ID Title
EUVD EUVD EUVD-2018-11261 GitLab CE 8.17 and later and EE 8.3 and later have a symlink time-of-check-to-time-of-use race condition that would allow unauthorized access to files in the GitLab Pages chroot environment. This is fixed in versions 11.5.1, 11.4.8, and 11.3.11.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T11:37:11.524Z

Reserved: 2018-11-26T00:00:00

Link: CVE-2018-19572

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-07-10T16:15:10.727

Modified: 2024-11-21T03:58:12.257

Link: CVE-2018-19572

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.