MEDIUM

CVE-2019-15726

Gitlab GitLab 2019-09-16 CVSS v3.1
CVSS
5.3

Description

An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Embedded images and media files in markdown could be pointed to an arbitrary server, which would reveal the IP address of clients requesting the file from that server.

Summary dbcve.org

GitLab allows embedding images and media files in markdown. When users view markdown content containing references to external servers, their client IP addresses are disclosed to those arbitrary third-party servers when the browser requests the external resources. This is an information disclosure vulnerability affecting all users viewing crafted markdown content.

Mitigation

Upgrade GitLab to version 12.2.1 or later. Alternatively, implement network-level controls to proxy or block external resource requests from client browsers.

EPSS Score

1.65%
Probability of exploitation in next 30 days
75.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE