HIGH
CVE-2019-12430
CVSS
8.8
Description
An issue was discovered in GitLab Community and Enterprise Edition 11.11. A specially crafted payload would allow an authenticated malicious user to execute commands remotely through the repository download feature. It allows Command Injection.
Summary dbcve.org
Command injection vulnerability in GitLab Community and Enterprise Edition 11.11 allows an authenticated malicious user to execute arbitrary commands on the server through the repository download feature by submitting a specially crafted payload.
Mitigation
Upgrade GitLab to the latest patched version. If immediate patching is not possible, restrict repository download functionality to trusted users and monitor for suspicious activity.
Weakness (CWE)
CWE-77
Command Injection
EPSS Score
2.64%
Probability of exploitation in next 30 days
84.9th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.