CVE-2019-15724: XSS
Published Sep 16, 2019
·Updated
An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.2.1. Label descriptions are vulnerable to HTML injection.
Affected Software
6 affected components
GitLab GitLab>=11.10.0<12.0.8
GitLab GitLab>=11.10.0<12.0.8
GitLab GitLab>=12.1.0<12.1.8
GitLab GitLab>=12.1.0<12.1.8
GitLab GitLab>=12.2.0<12.2.3
GitLab GitLab>=12.2.0<12.2.3
Event History
Sep 16, 2019
CVE Published
via MITRE·04:48 PM
Data Sourced
via MITRE·04:48 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-15724?
CVE-2019-15724 has a medium severity rating due to its potential for HTML injection in label descriptions.
2
How do I fix CVE-2019-15724?
To fix CVE-2019-15724, users should upgrade to GitLab versions 12.2.3 or later.
3
What versions of GitLab are affected by CVE-2019-15724?
CVE-2019-15724 affects GitLab Community and Enterprise Editions from version 11.10.0 up to 12.2.1.
4
What type of vulnerability is CVE-2019-15724?
CVE-2019-15724 is an HTML injection vulnerability that affects GitLab label descriptions.
5
Can CVE-2019-15724 lead to other attacks?
Yes, CVE-2019-15724 can lead to cross-site scripting (XSS) attacks if exploited.