{"api_version":"1","generated_at":"2026-07-23T13:40:23+00:00","cve":"CVE-2019-13004","urls":{"html":"https://cve.report/CVE-2019-13004","api":"https://cve.report/api/cve/CVE-2019-13004.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-13004","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-13004"},"summary":{"title":"CVE-2019-13004","description":"An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.0.2. When specific encoded characters were added to comments, the comments section would become inaccessible. It has Incorrect Access Control (issue 1 of 2).","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2020-03-10 15:15:00","updated_at":"2020-03-11 18:30:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"https://about.gitlab.com/releases/2019/07/03/security-release-gitlab-12-dot-0-dot-3-released/","name":"https://about.gitlab.com/releases/2019/07/03/security-release-gitlab-12-dot-0-dot-3-released/","refsource":"CONFIRM","tags":["Release Notes","Vendor Advisory"],"title":"GitLab Security Release: 12.0.3, 11.11.5, and 11.10.8\n|\nGitLab","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://about.gitlab.com/blog/categories/releases/","name":"https://about.gitlab.com/blog/categories/releases/","refsource":"MISC","tags":["Release Notes","Vendor Advisory"],"title":"Releases\n|\nGitLab","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-13004","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-13004","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"13004","vulnerable":"1","versionEndIncluding":"12.0.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gitlab","cpe5":"gitlab","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"community","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"13004","vulnerable":"1","versionEndIncluding":"12.0.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gitlab","cpe5":"gitlab","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2019-13004","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.0.2. When specific encoded characters were added to comments, the comments section would become inaccessible. It has Incorrect Access Control (issue 1 of 2)."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://about.gitlab.com/blog/categories/releases/","refsource":"MISC","name":"https://about.gitlab.com/blog/categories/releases/"},{"refsource":"CONFIRM","name":"https://about.gitlab.com/releases/2019/07/03/security-release-gitlab-12-dot-0-dot-3-released/","url":"https://about.gitlab.com/releases/2019/07/03/security-release-gitlab-12-dot-0-dot-3-released/"}]}},"nvd":{"publishedDate":"2020-03-10 15:15:00","lastModifiedDate":"2020-03-11 18:30:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":3.9,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.10.0","versionEndIncluding":"12.0.2","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.10.0","versionEndIncluding":"12.0.2","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"13004","Ordinal":"151359","Title":"CVE-2019-13004","CVE":"CVE-2019-13004","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"13004","Ordinal":"1","NoteData":"An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.0.2. When specific encoded characters were added to comments, the comments section would become inaccessible. It has Incorrect Access Control (issue 1 of 2).","Type":"Description","Title":null},{"CveYear":"2019","CveId":"13004","Ordinal":"2","NoteData":"2020-03-10","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"13004","Ordinal":"3","NoteData":"2020-03-10","Type":"Other","Title":"Modified"}]}}}