CVE-2018-19493: GitLab

Medium severity, CVSS 6.1. EPSS: 1.3% chance of exploitation in the next 30 days.

An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is a persistent XSS vulnerability in the environment pages due to a lack of input validation and output encoding.

Affected products

  • GitLab GitLab: from 11.0.0, before 11.3.11 (fixed in 11.3.11); from 11.4.0, before 11.4.8 (fixed in 11.4.8); from 11.5.0, before 11.5.1 (fixed in 11.5.1)

Published 2019-07-10. Last modified 2026-06-17.