CVE-2019-19628

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
05/01/2020
Last modified:
10/01/2020

Description

In GitLab EE 11.3 through 12.5.3, 12.4.5, and 12.3.8, insufficient parameter sanitization for the Maven package registry could lead to privilege escalation and remote code execution vulnerabilities under certain conditions.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* 11.3.0 (including) 12.3.8 (including)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* 12.4.0 (including) 12.4.5 (including)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* 12.5.0 (including) 12.5.3 (including)