CVE-2019-19311: XSS
Published Jan 3, 2020
·Updated
GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 allows XSS in group and profile fields.
Affected Software
3 affected components
GitLab GitLab>=8.14.0<12.3.7
GitLab GitLab>=12.4.0<12.4.4
GitLab GitLab>=12.5.0<12.5.1
Event History
Jan 3, 2020
CVE Published
via MITRE·03:22 PM
Data Sourced
via MITRE·03:22 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-19311?
CVE-2019-19311 has been rated as a medium severity vulnerability due to its potential for XSS attacks.
2
How do I fix CVE-2019-19311?
To fix CVE-2019-19311, you should upgrade your GitLab instance to a version newer than 12.5.1.
3
Which versions of GitLab are affected by CVE-2019-19311?
CVE-2019-19311 affects GitLab EE versions from 8.14 through 12.5, as well as 12.4.3 and 12.3.6.
4
What type of vulnerability is CVE-2019-19311?
CVE-2019-19311 is an XSS (Cross-Site Scripting) vulnerability that affects group and profile fields.
5
Can CVE-2019-19311 be exploited remotely?
Yes, CVE-2019-19311 can be exploited remotely, potentially allowing attackers to inject malicious scripts.