MEDIUM

CVE-2019-19311

Gitlab GitLab 2020-01-03 CVSS v3.1
CVSS
5.4

Description

GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 allows XSS in group and profile fields.

Summary dbcve.org

GitLab EE versions 8.14 through 12.5, 12.4.3, and 12.3.6 contain a stored Cross-Site Scripting (XSS) vulnerability in group and profile fields. User-supplied input in these fields is not properly sanitized or encoded when rendered, allowing malicious scripts to execute in the browsers of other users viewing these fields.

Mitigation

Upgrade to a patched GitLab version. As an interim control, implement proper output encoding and input validation on group and profile field rendering, or restrict field input through a WAF with XSS rules.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

0.73%
Probability of exploitation in next 30 days
52.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE