HIGH

CVE-2019-12430

Gitlab GitLab 2020-03-10 CVSS v3.1
CVSS
8.8

Description

An issue was discovered in GitLab Community and Enterprise Edition 11.11. A specially crafted payload would allow an authenticated malicious user to execute commands remotely through the repository download feature. It allows Command Injection.

Summary dbcve.org

Command injection vulnerability in GitLab Community and Enterprise Edition 11.11 allows an authenticated malicious user to execute arbitrary commands on the server through the repository download feature by submitting a specially crafted payload.

Mitigation

Upgrade GitLab to the latest patched version. If immediate patching is not possible, restrict repository download functionality to trusted users and monitor for suspicious activity.

Weakness (CWE)

CWE-77 Command Injection

EPSS Score

2.64%
Probability of exploitation in next 30 days
84.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE