CVE-2019-19628Path Traversal in Gitlab

CWE-22Path Traversal4 documents4 sources
Severity
9.8CRITICALNVD
EPSS
2.1%
top 15.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 5
Latest updateMay 24

Description

In GitLab EE 11.3 through 12.5.3, 12.4.5, and 12.3.8, insufficient parameter sanitization for the Maven package registry could lead to privilege escalation and remote code execution vulnerabilities under certain conditions.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

NVDgitlab/gitlab11.3.012.3.8+2
debiandebian/gitlab
gitlabgitlab/gitlab

🔴Vulnerability Details

1
GHSA
GHSA-wfj3-6j6g-rpwx: In GitLab EE 112022-05-24

📋Vendor Advisories

2
GitLab
CVE-2019-19628: In GitLab EE 11.3 through 12.5.3, 12.4.5, and 12.3.8, insufficient parameter sanitization for the Maven package registry could lead to privilege escal2020-01-05
Debian
CVE-2019-19628: gitlab - In GitLab EE 11.3 through 12.5.3, 12.4.5, and 12.3.8, insufficient parameter san...2019