Input validation error in Gitlab Community Edition - CVE-2019-6795

 

Input validation error in Gitlab Community Edition - CVE-2019-6795

Published: September 9, 2019 / Updated: July 17, 2020


Vulnerability identifier: #VU30775
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-6795
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Insufficient Visual Distinction of Homoglyphs Presented to a User. IDN homographs and RTLO characters are rendered to unicode, which could be used for social engineering.


Affected software

Gitlab Community Edition

How to mitigate CVE-2019-6795

Install update from vendor's website.

Gitlab Community Edition - update to 11.7.1

External References

Related Security Bulletins