First published: Tue Mar 10 2020(Updated: )
An issue was discovered in GitLab Enterprise Edition 11.7 through 11.11. The epic details page contained a lack of input validation and output encoding issue which resulted in a persistent XSS vulnerability on child epics.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=11.7.0<=11.11.0 | |
GitLab | >=11.7.0<=11.11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-12442 has a medium severity rating due to its potential for exploitation through persistent XSS.
To fix CVE-2019-12442, upgrade GitLab to a version later than 11.11.0.
CVE-2019-12442 is associated with persistent cross-site scripting (XSS) attacks.
CVE-2019-12442 affects GitLab Enterprise Edition from versions 11.7.0 to 11.11.0.
You can identify vulnerability to CVE-2019-12442 by checking if your GitLab instance is running a version between 11.7.0 and 11.11.0.