In GitLab EE 11.3 through 12.5.3, 12.4.5, and 12.3.8, insufficient parameter sanitization for the Maven package registry could lead to privilege escalation and remote code execution vulnerabilities under certain conditions.
{
"cpe": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
"extracted_events": [
{
"introduced": "11.3.0"
},
{
"last_affected": "12.3.8"
},
{
"introduced": "12.4.0"
},
{
"last_affected": "12.4.5"
},
{
"introduced": "12.5.0"
},
{
"last_affected": "12.5.3"
}
],
"source": "CPE_RANGE"
}