CVE-2019-12442: XSS
Published Mar 10, 2020
·Updated
An issue was discovered in GitLab Enterprise Edition 11.7 through 11.11. The epic details page contained a lack of input validation and output encoding issue which resulted in a persistent XSS vulnerability on child epics.
Affected Software
2 affected components
GitLab GitLab>=11.7.0<=11.11.0
GitLab GitLab>=11.7.0<=11.11.0
Event History
Mar 10, 2020
CVE Published
via MITRE·02:38 PM
Data Sourced
via MITRE·02:38 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-12442?
CVE-2019-12442 has a medium severity rating due to its potential for exploitation through persistent XSS.
2
How do I fix CVE-2019-12442?
To fix CVE-2019-12442, upgrade GitLab to a version later than 11.11.0.
3
What types of attacks are associated with CVE-2019-12442?
CVE-2019-12442 is associated with persistent cross-site scripting (XSS) attacks.
4
Which versions of GitLab are affected by CVE-2019-12442?
CVE-2019-12442 affects GitLab Enterprise Edition from versions 11.7.0 to 11.11.0.
5
How can I identify if I'm vulnerable to CVE-2019-12442?
You can identify vulnerability to CVE-2019-12442 by checking if your GitLab instance is running a version between 11.7.0 and 11.11.0.