First published: Fri Jan 03 2020(Updated: )
GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 allows XSS in group and profile fields.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=8.14.0<12.3.7 | |
GitLab | >=12.4.0<12.4.4 | |
GitLab | >=12.5.0<12.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-19311 has been rated as a medium severity vulnerability due to its potential for XSS attacks.
To fix CVE-2019-19311, you should upgrade your GitLab instance to a version newer than 12.5.1.
CVE-2019-19311 affects GitLab EE versions from 8.14 through 12.5, as well as 12.4.3 and 12.3.6.
CVE-2019-19311 is an XSS (Cross-Site Scripting) vulnerability that affects group and profile fields.
Yes, CVE-2019-19311 can be exploited remotely, potentially allowing attackers to inject malicious scripts.