CVE-2019-12445: XSS
An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. A malicious user could execute JavaScript code on notes by importing a specially crafted project file. It allows XSS.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-12445?
CVE-2019-12445 has a high severity rating due to the potential for Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2019-12445?
To fix CVE-2019-12445, upgrade GitLab to the latest version beyond 11.11.0.
What types of software are affected by CVE-2019-12445?
CVE-2019-12445 affects both GitLab Community and GitLab Enterprise editions from versions 8.4 to 11.11.
What exploitation vectors exist for CVE-2019-12445?
Exploitation of CVE-2019-12445 occurs when a malicious user imports a specially crafted project file containing malicious JavaScript.
What are the potential impacts of CVE-2019-12445?
The potential impacts of CVE-2019-12445 include unauthorized execution of JavaScript and compromise of user sessions or sensitive information.