CVE-2019-12444: XSS
Published Mar 10, 2020
·Updated
An issue was discovered in GitLab Community and Enterprise Edition 8.9 through 11.11. Wiki Pages contained a lack of input validation which resulted in a persistent XSS vulnerability.
Affected Software
2 affected components
GitLab GitLab>=8.9.0<=11.11.0
GitLab GitLab>=8.9.0<=11.11.0
Event History
Mar 10, 2020
CVE Published
via MITRE·02:42 PM
Data Sourced
via MITRE·02:42 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-12444?
CVE-2019-12444 is classified as a medium severity vulnerability due to its persistent XSS nature.
2
How do I fix CVE-2019-12444?
To fix CVE-2019-12444, upgrade GitLab Community or Enterprise Edition to version 11.11.1 or later.
3
What versions of GitLab are affected by CVE-2019-12444?
CVE-2019-12444 affects GitLab versions from 8.9.0 to 11.11.0.
4
What type of vulnerability is CVE-2019-12444?
CVE-2019-12444 is a persistent cross-site scripting (XSS) vulnerability.
5
Can CVE-2019-12444 be exploited remotely?
Yes, CVE-2019-12444 can be exploited remotely through maliciously crafted wiki pages.