gitlab-rails-ce-18.3
Chainguard
Status
Impact
Component activestorage is at a vulnerable version 7.1.5.1. The vulnerability is fixed in version 7.1.5.2. GitLab advises that maintainers should NOT upgrade dependency versions, as their automation would have already applied this in cases of simple version increments. If a dependency version has not yet been upgraded, there is usually a good reason. Additionally, past attempts to upgrade GitLab dependencies ahead of the upstream release have resulted in build issues.
Status