← Back

CVE-2019-19628

nvd nist
Published: Jan 5, 2020Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

In GitLab EE 11.3 through 12.5.3, 12.4.5, and 12.3.8, insufficient parameter sanitization for the Maven package registry could lead to privilege escalation and remote code execution vulnerabilities under certain conditions.

Affected (3)

Products: Gitlab: Gitlab
1 product
Gitlab
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Gitlab
From 11.3.0 to 12.3.8
From 12.4.0 to 12.4.5
From 12.5.0 to 12.5.3

References (4)

Timeline

No history available yet.