MEDIUM
CVE-2019-12445
CVSS
5.4
Description
An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. A malicious user could execute JavaScript code on notes by importing a specially crafted project file. It allows XSS.
Summary dbcve.org
A stored XSS vulnerability in GitLab Community and Enterprise Edition versions 8.4 through 11.11 allows a malicious user to execute arbitrary JavaScript code within notes by importing a specially crafted project file, bypassing existing sanitization controls.
Mitigation
Upgrade GitLab to the latest patched version (11.11.1 or later) to remediate this vulnerability. As a temporary measure, restrict import capabilities for untrusted users until the upgrade is completed.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
0.58%
Probability of exploitation in next 30 days
46.2th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.