CVE-2019-11547
Summary
| CVE | CVE-2019-11547 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-09-09 19:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It has Improper Encoding or Escaping of Output. The branch name on new merge request notification emails isn't escaped, which could potentially lead to XSS issues. |
Risk And Classification
Problem Types: CWE-79 | CWE-116
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| GitLab Security Release: 11.10.2, 11.9.10, and 11.8.9 | GitLab | CONFIRM | about.gitlab.com | Release Notes, Vendor Advisory |
| Persistent XSS via e-mail when adding an approver to a merge request (#11515) · Issues · GitLab.org / GitLab · GitLab | CONFIRM | gitlab.com | Exploit, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.