CVE-2019-5467: XSS
Published Sep 9, 2019
·Updated
An input validation and output encoding issue was discovered in the GitLab CE/EE wiki pages feature which could result in a persistent XSS. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.
Affected Software
6 affected components
GitLab GitLab>=11.11.2<11.11.7
GitLab GitLab>=11.11.2<11.11.7
GitLab GitLab>=12.0.0<12.0.4
GitLab GitLab>=12.0.0<12.0.4
GitLab GitLab>=12.1.0<12.1.2
GitLab GitLab>=12.1.0<12.1.2
Event History
Sep 9, 2019
CVE Published
via MITRE·05:45 PM
Data Sourced
via MITRE·05:45 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-5467?
CVE-2019-5467 has been classified as a moderate severity vulnerability.
2
How do I fix CVE-2019-5467?
To fix CVE-2019-5467, update GitLab to version 12.1.2, 12.0.4, or 11.11.6 or later.
3
What type of vulnerability is CVE-2019-5467?
CVE-2019-5467 is an input validation and output encoding issue that can lead to a persistent cross-site scripting (XSS) exploit.
4
Which versions of GitLab are affected by CVE-2019-5467?
CVE-2019-5467 affects GitLab versions prior to 12.1.2, 12.0.4, and 11.11.6.
5
Is CVE-2019-5467 applicable to GitLab CE and EE?
Yes, CVE-2019-5467 affects both GitLab Community Edition (CE) and Enterprise Edition (EE).