Cross-site scripting in Gitlab Community Edition - CVE-2019-10111

 

Cross-site scripting in Gitlab Community Edition - CVE-2019-10111

Published: May 15, 2019 / Updated: July 17, 2020


Vulnerability identifier: #VU31071
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
CVE-ID: CVE-2019-10111
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: GitLab, Inc
Affected software:
Gitlab Community Edition

Detailed vulnerability description

The vulnerability allows a remote authenticated user to read and manipulate data.

An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. It allows persistent XSS in the merge request "resolve conflicts" page.


How to mitigate CVE-2019-10111

Install update from vendor's website.

Sources