MEDIUM
CVE-2019-15739
CVSS
6.1
Description
An issue was discovered in GitLab Community and Enterprise Edition 8.1 through 12.2.1. Certain areas displaying Markdown were not properly sanitizing some XSS payloads.
Summary dbcve.org
A stored Cross-Site Scripting (XSS) vulnerability exists in GitLab Community and Enterprise Edition versions 8.1 through 12.2.1. Certain areas that display Markdown content fail to properly sanitize malicious XSS payloads, allowing attackers to inject and execute arbitrary JavaScript in the browsers of users viewing the affected Markdown content.
Mitigation
Upgrade GitLab to version 12.2.2 or later. If immediate patching is not possible, restrict or sanitize Markdown input in affected areas until the upgrade can be completed.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
1.16%
Probability of exploitation in next 30 days
65.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.