CVE-2019-19313Improper Handling of Exceptional Conditions in Gitlab

Severity
7.5HIGHNVD
EPSS
0.3%
top 51.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 5
Latest updateMay 24

Description

GitLab EE 12.3 through 12.5, 12.4.3, and 12.3.6 allows Denial of Service. Certain characters were making it impossible to create, edit, or view issues and commits.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

NVDgitlab/gitlab12.3.012.3.8+2
debiandebian/gitlab
gitlabgitlab/gitlab

🔴Vulnerability Details

1
GHSA
GHSA-m874-44cm-939v: GitLab EE 122022-05-24

📋Vendor Advisories

2
GitLab
CVE-2019-19313: GitLab EE 12.3 through 12.5, 12.4.3, and 12.3.6 allows Denial of Service. Certain characters were making it impossible to create, edit, or view issues2020-01-05
Debian
CVE-2019-19313: gitlab - GitLab EE 12.3 through 12.5, 12.4.3, and 12.3.6 allows Denial of Service. Certai...2019