First published: Tue Mar 10 2020(Updated: )
An issue was discovered in GitLab Community and Enterprise Edition 8.9 through 11.11. Wiki Pages contained a lack of input validation which resulted in a persistent XSS vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=8.9.0<=11.11.0 | |
GitLab | >=8.9.0<=11.11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-12444 is classified as a medium severity vulnerability due to its persistent XSS nature.
To fix CVE-2019-12444, upgrade GitLab Community or Enterprise Edition to version 11.11.1 or later.
CVE-2019-12444 affects GitLab versions from 8.9.0 to 11.11.0.
CVE-2019-12444 is a persistent cross-site scripting (XSS) vulnerability.
Yes, CVE-2019-12444 can be exploited remotely through maliciously crafted wiki pages.