MEDIUM

CVE-2019-15739

Gitlab GitLab 2019-09-16 CVSS v3.1
CVSS
6.1

Description

An issue was discovered in GitLab Community and Enterprise Edition 8.1 through 12.2.1. Certain areas displaying Markdown were not properly sanitizing some XSS payloads.

Summary dbcve.org

A stored Cross-Site Scripting (XSS) vulnerability exists in GitLab Community and Enterprise Edition versions 8.1 through 12.2.1. Certain areas that display Markdown content fail to properly sanitize malicious XSS payloads, allowing attackers to inject and execute arbitrary JavaScript in the browsers of users viewing the affected Markdown content.

Mitigation

Upgrade GitLab to version 12.2.2 or later. If immediate patching is not possible, restrict or sanitize Markdown input in affected areas until the upgrade can be completed.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

1.16%
Probability of exploitation in next 30 days
65.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE