| Vulnerability Name: | CVE-2019-13004 (CCN-177632) | ||||||||||||
| Assigned: | 2019-07-03 | ||||||||||||
| Published: | 2019-07-03 | ||||||||||||
| Updated: | 2020-03-11 | ||||||||||||
| Summary: | An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.0.2. When specific encoded characters were added to comments, the comments section would become inaccessible. It has Incorrect Access Control (issue 1 of 2). | ||||||||||||
| CVSS v3 Severity: | 5.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L) 4.6 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C) 
 4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C) 
  | ||||||||||||
| CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
 
  | ||||||||||||
| Vulnerability Type: | CWE-Other | ||||||||||||
| Vulnerability Consequences: | Denial of Service | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2019-13004 Source: MISC Type: Release Notes, Vendor Advisory https://about.gitlab.com/blog/categories/releases/ Source: CCN Type: GitLab Web site GitLab Security Release: 12.0.3, 11.11.5, and 11.10.8 Source: CONFIRM Type: Release Notes, Vendor Advisory https://about.gitlab.com/releases/2019/07/03/security-release-gitlab-12-dot-0-dot-3-released/ Source: XF Type: UNKNOWN gitlab-cve201913004-dos(177632)  | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1:   Denotes that component is vulnerable | ||||||||||||
| Oval Definitions | |||||||||||||
  | |||||||||||||
| BACK | |||||||||||||