CVE-2019-5468: GitLab
High severity, CVSS 8.8. EPSS: 2.1% chance of exploitation in the next 30 days.
An privilege escalation issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 when Mattermost slash commands are used with a blocked account.
Affected products
- GitLab GitLab: from 11.11.0, before 11.11.6 (fixed in 11.11.6); from 12.0.0, before 12.0.4 (fixed in 12.0.4); from 12.1.0, before 12.1.2 (fixed in 12.1.2)
Published 2020-01-28. Last modified 2026-06-17.