CVE-2019-19628

Source
https://cve.org/CVERecord?id=CVE-2019-19628
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-19628.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-19628
Published
2020-01-05T22:15:11Z
Modified
2026-08-27T18:53:18Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

In GitLab EE 11.3 through 12.5.3, 12.4.5, and 12.3.8, insufficient parameter sanitization for the Maven package registry could lead to privilege escalation and remote code execution vulnerabilities under certain conditions.

References

Affected packages

Git / gitlab.com/gitlab-org/gitlab

Affected ranges

Type
GIT
Repo
https://gitlab.com/gitlab-org/gitlab
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
    "extracted_events": [
        {
            "introduced": "11.3.0"
        },
        {
            "last_affected": "12.3.8"
        },
        {
            "introduced": "12.4.0"
        },
        {
            "last_affected": "12.4.5"
        },
        {
            "introduced": "12.5.0"
        },
        {
            "last_affected": "12.5.3"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

v12.*
v12.4.0-ee
v12.4.2-ee
v12.4.3-ee
v12.4.5-ee
v12.5.0-ee
v12.5.3-ee

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-19628.json"