#VU30775 Input validation error in Gitlab Community Edition - CVE-2019-6795

 

#VU30775 Input validation error in Gitlab Community Edition - CVE-2019-6795

Published: September 9, 2019 / Updated: July 17, 2020


Vulnerability identifier: #VU30775
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2019-6795
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Gitlab Community Edition
Software vendor:
GitLab, Inc

Description

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Insufficient Visual Distinction of Homoglyphs Presented to a User. IDN homographs and RTLO characters are rendered to unicode, which could be used for social engineering.


Remediation

Install update from vendor's website.

External links