ZeroHour

CVE-2019-6781

CVSS 3.1
7.5 high
EPSS
1%p66
Published
()
Modified
Description

An Improper Input Validation issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It was possible to use the profile name to inject a potentially malicious link into notification emails.

Vendors
gitlab
Products
gitlab
Weakness
CWE-601
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.