CVE-2019-14944: Command Injection
An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Gitaly allows injection of command-line flags. This sometimes leads to privilege escalation or remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-14944?
CVE-2019-14944 has a severity rating that may allow for privilege escalation or remote code execution if exploited.
How do I fix CVE-2019-14944?
To fix CVE-2019-14944, you should upgrade your GitLab Community or Enterprise Edition to versions 11.11.8, 12.0.6, or 12.1.6 or later.
What systems are affected by CVE-2019-14944?
CVE-2019-14944 affects GitLab Community and Enterprise Editions prior to versions 11.11.8, 12.0.6, and 12.1.6.
What type of attack can CVE-2019-14944 facilitate?
CVE-2019-14944 can facilitate command injection, potentially leading to privilege escalation or remote code execution.
Is CVE-2019-14944 a critical vulnerability?
Yes, CVE-2019-14944 is considered a critical vulnerability due to its potential impact on system security.