Insufficient Parameter Sanitization in GitLab EE Maven Package Registry: Privilege Escalation and Remote Code Execution Vulnerabilities

Insufficient Parameter Sanitization in GitLab EE Maven Package Registry: Privilege Escalation and Remote Code Execution Vulnerabilities

CVE-2019-19628 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In GitLab EE 11.3 through 12.5.3, 12.4.5, and 12.3.8, insufficient parameter sanitization for the Maven package registry could lead to privilege escalation and remote code execution vulnerabilities under certain conditions.

Learn more about our Web Application Penetration Testing UK.