4

CVE-2019-5461

Exploit
An input validation problem was discovered in the GitHub service integration which could result in an attacker being able to make arbitrary POST requests in a GitLab instance's internal network. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GitlabGitLab SwEditioncommunity Version >= 11.11.0 < 11.11.7
GitlabGitLab SwEditionenterprise Version >= 11.11.0 < 11.11.7
GitlabGitLab SwEditioncommunity Version >= 12.0.0 < 12.0.4
GitlabGitLab SwEditionenterprise Version >= 12.0.0 < 12.0.4
GitlabGitLab SwEditioncommunity Version >= 12.1.0 < 12.1.2
GitlabGitLab SwEditionenterprise Version >= 12.1.0 < 12.1.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.08% 0.243
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 3.5 2.1 1.4
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:P/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.