CVE-2019-5468: GitLab

High severity, CVSS 8.8. EPSS: 2.1% chance of exploitation in the next 30 days.

An privilege escalation issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 when Mattermost slash commands are used with a blocked account.

Affected products

  • GitLab GitLab: from 11.11.0, before 11.11.6 (fixed in 11.11.6); from 12.0.0, before 12.0.4 (fixed in 12.0.4); from 12.1.0, before 12.1.2 (fixed in 12.1.2)

Published 2020-01-28. Last modified 2026-06-17.