MEDIUM
CVE-2019-12442
CVSS
6.1
Description
An issue was discovered in GitLab Enterprise Edition 11.7 through 11.11. The epic details page contained a lack of input validation and output encoding issue which resulted in a persistent XSS vulnerability on child epics.
Summary dbcve.org
A persistent XSS vulnerability exists in GitLab Enterprise Edition 11.7-11.11 on the epic details page. The application fails to properly validate input and encode output when handling child epics, allowing attackers to inject malicious JavaScript that executes in the browsers of other users viewing those epics.
Mitigation
Upgrade GitLab Enterprise Edition to version 11.12 or later to receive the security patch, or apply the available GitLab security patch for this vulnerability.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
0.69%
Probability of exploitation in next 30 days
51.4th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.