CVE-2018-3710

Severity
7.8HIGH
EPSS
4.2%
top 11.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 21
Latest updateMay 13

Description

Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable to an Insecure Temporary File in the project import component resulting remote code execution.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5gitlab/gitlab_community_and_enterprise_editions10.2.0 - 10.2.5 Fixed in 10.2.6, 10.3.0 - 10.3.3 Fixed in 10.3.4, 8.9 - 10.1.5 Fixed in 10.1.6+2
NVDgitlab/gitlab8.9.09.5.10+6

Also affects: Debian Linux 9.0

🔴Vulnerability Details

2
GHSA
GHSA-w2fx-qxhw-34qh: Gitlab Community and Enterprise Editions version 102022-05-13
CVEList
CVE-2018-3710: Gitlab Community and Enterprise Editions version 102018-03-21

📋Vendor Advisories

2
GitLab
CVE-2018-3710: Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable to an Insecure Temporary File in the project import component resulting remote c2018-03-21
Debian
CVE-2018-3710: gitlab - Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable to an Inse...2018
CVE-2018-3710 (HIGH CVSS 7.8) | Gitlab Community and Enterprise Edi | cvebase.io