Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2018-19585CRLF Injection in Gitlab

CWE-93CRLF Injection6 documents5 sources
Severity
7.5HIGHNVD
EPSS
11.5%
top 6.35%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedMay 17
Latest updateMay 24

Description

GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1 have CRLF Injection in Project Mirroring when using the Git protocol.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

NVDgitlab/gitlab8.18.011.3.11+2
debiandebian/gitlab< gitlab 11.3.11+dfsg-1 (sid)
gitlabgitlab/gitlab

🔴Vulnerability Details

1
GHSA
GHSA-49rg-2gmx-qjmr: GitLab CE/EE versions 82022-05-24

💥Exploits & PoCs

2
Exploit-DB
GitLab 11.4.7 - RCE (Authenticated) (2)2020-12-24
Exploit-DB
GitLab 11.4.7 - Remote Code Execution (Authenticated) (1)2020-12-14

📋Vendor Advisories

2
GitLab
CVE-2018-19585: GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1 have CRLF Injection in Project Mirroring when usi2019-05-17
Debian
CVE-2018-19585: gitlab - GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11.4.8, and ...2018