Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

HTTP:GITLAB-WIKI-API-RCE

Severity

Major

Recommended

Yes

Recommended Action

Drop

Category

HTTP

Keywords

GitLab Wiki API CVE-2018-18649 Remote Code Execution

Release Date

2019/01/22

Update Number

3136

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

HTTP: GitLab Wiki API CVE-2018-18649 Remote Code Execution


This signature detects attempts to exploit a known vulnerability against GitLab Wiki API. A successful attack can lead to arbitrary code execution.

Extended Description

An issue was discovered in the wiki API in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows for remote code execution.

Affected Products

  • Gitlab gitlab 11.3.0
  • Gitlab gitlab 11.3.1
  • Gitlab gitlab 11.3.2
  • Gitlab gitlab 11.3.3
  • Gitlab gitlab 11.3.4
  • Gitlab gitlab 11.3.5
  • Gitlab gitlab 11.3.6
  • Gitlab gitlab 11.3.7
  • Gitlab gitlab 11.4.0
  • Gitlab gitlab 11.4.1
  • Gitlab gitlab 11.4.2

References

  • CVE: CVE-2018-18649
  • URL: https://about.gitlab.com/2018/10/29/security-release-gitlab-11-dot-4-dot-3-released/
  • URL: https://gitlab.com/gitlab-org/gitlab-ce/issues/53072

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out