CVE-2019-5471
EUVD-2019-1505309.09.2019, 18:15
An input validation and output encoding issue was discovered in the GitLab email notification feature which could result in a persistent XSS. This was addressed in GitLab 12.1.2, 12.0.4, and 11.11.6.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| gitlab | gitlab | 11.11.0 ≤ 𝑥 < 11.11.7 |
| gitlab | gitlab | 11.11.0 ≤ 𝑥 < 11.11.7 |
| gitlab | gitlab | 12.0.0 ≤ 𝑥 < 12.0.4 |
| gitlab | gitlab | 12.0.0 ≤ 𝑥 < 12.0.4 |
| gitlab | gitlab | 12.1.0 ≤ 𝑥 < 12.1.2 |
| gitlab | gitlab | 12.1.0 ≤ 𝑥 < 12.1.2 |
𝑥
= Vulnerable software versions