CVE-2019-18454: XSS
Published Nov 26, 2019
·Updated
An issue was discovered in GitLab Community and Enterprise Edition 10.5 through 12.4 in link validation for RDoc wiki pages feature. It has XSS.
Affected Software
2 affected components
GitLab GitLab>=10.5.0<=12.4.0
GitLab GitLab>=10.5.0<=12.4.0
Event History
Nov 26, 2019
CVE Published
via MITRE·04:31 PM
Data Sourced
via MITRE·04:31 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-18454?
CVE-2019-18454 is classified as a medium severity vulnerability due to its potential for XSS attacks.
2
How do I fix CVE-2019-18454?
To fix CVE-2019-18454, upgrade GitLab to version 12.4.1 or later.
3
What applications are affected by CVE-2019-18454?
CVE-2019-18454 affects GitLab Community and Enterprise Edition versions from 10.5.0 to 12.4.0.
4
What type of vulnerability is CVE-2019-18454?
CVE-2019-18454 is an XSS (Cross-Site Scripting) vulnerability affecting the RDoc wiki pages feature.
5
Can CVE-2019-18454 be exploited remotely?
Yes, CVE-2019-18454 can be exploited remotely by an attacker to execute malicious scripts.