CVE-2019-19311: GitLab
Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.
GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 allows XSS in group and profile fields.
Affected products
- GitLab GitLab: from 8.14.0, before 12.3.7 (fixed in 12.3.7); from 12.4.0, before 12.4.4 (fixed in 12.4.4); from 12.5.0, before 12.5.1 (fixed in 12.5.1)
Published 2020-01-03. Last modified 2026-06-17.