Security Advisory

CVE-2018-19572

5.9
MEDIUM

Vulnerability Description

GitLab CE 8.17 and later and EE 8.3 and later have a symlink time-of-check-to-time-of-use race condition that would allow unauthorized access to files in the GitLab Pages chroot environment. This is fixed in versions 11.5.1, 11.4.8, and 11.3.11.
Published Date July 10, 2019
Official Source NIST NVD Advisory