← Back

CVE-2019-19628

nvd nist
Published: Jan 5, 2020Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

In GitLab EE 11.3 through 12.5.3, 12.4.5, and 12.3.8, insufficient parameter sanitization for the Maven package registry could lead to privilege escalation and remote code execution vulnerabilities under certain conditions.

Affected (3)

Products: Gitlab: Gitlab
1 product
Gitlab
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Gitlab
From 11.3.0 to 12.3.8
From 12.4.0 to 12.4.5
From 12.5.0 to 12.5.3

References (4)

Timeline

No history available yet.