CVE-2019-15739: XSS
Published Sep 16, 2019
·Updated
An issue was discovered in GitLab Community and Enterprise Edition 8.1 through 12.2.1. Certain areas displaying Markdown were not properly sanitizing some XSS payloads.
Affected Software
6 affected components
GitLab GitLab>=8.1.0<12.0.8
GitLab GitLab>=8.1.0<12.0.8
GitLab GitLab>=12.1.0<12.1.8
GitLab GitLab>=12.1.0<12.1.8
GitLab GitLab>=12.2.0<12.2.3
GitLab GitLab>=12.2.0<12.2.3
Event History
Sep 16, 2019
CVE Published
via MITRE·05:04 PM
Data Sourced
via MITRE·05:04 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-15739?
The severity of CVE-2019-15739 is classified as a high severity vulnerability.
2
How do I fix CVE-2019-15739?
To fix CVE-2019-15739, upgrade GitLab to version 12.2.3 or later.
3
Which GitLab versions are affected by CVE-2019-15739?
CVE-2019-15739 affects GitLab Community and Enterprise Edition versions 8.1 to 12.2.1.
4
What type of vulnerability is CVE-2019-15739?
CVE-2019-15739 is an XSS (Cross-Site Scripting) vulnerability related to improper sanitization of Markdown.
5
Is user data at risk due to CVE-2019-15739?
Yes, CVE-2019-15739 can potentially expose user data to an attacker via XSS payloads.