MEDIUM

CVE-2019-12445

Gitlab GitLab 2020-03-10 CVSS v3.1
CVSS
5.4

Description

An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. A malicious user could execute JavaScript code on notes by importing a specially crafted project file. It allows XSS.

Summary dbcve.org

A stored XSS vulnerability in GitLab Community and Enterprise Edition versions 8.4 through 11.11 allows a malicious user to execute arbitrary JavaScript code within notes by importing a specially crafted project file, bypassing existing sanitization controls.

Mitigation

Upgrade GitLab to the latest patched version (11.11.1 or later) to remediate this vulnerability. As a temporary measure, restrict import capabilities for untrusted users until the upgrade is completed.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

0.58%
Probability of exploitation in next 30 days
46.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE