VulnerabilityModified
CVE-2019-14944
Gitaly allows injection of command-line flags.
MEDIUM 6.5EPSS 1.57%
Does this matter?
Lower severity and a low EPSS score (1.57%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Gitaly allows injection of command-line flags. This sometimes leads to privilege escalation or remote code execution.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
- EPSS
- 1.57% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-77
- Affected
- gitlab/gitlab
- Source
- cve@mitre.org
References
- https://about.gitlab.com/blog/categories/releases/Release Notes
- https://about.gitlab.com/releases/2019/08/12/critical-security-release-gitlab-12-dot-1-dot-6-released/Vendor Advisory
- https://gitlab.com/gitlab-org/gitaly/issues/1801Exploit, Issue Tracking, Vendor Advisory
- https://gitlab.com/gitlab-org/gitaly/issues/1802Broken Link
- https://about.gitlab.com/blog/categories/releases/Release Notes
- https://about.gitlab.com/releases/2019/08/12/critical-security-release-gitlab-12-dot-1-dot-6-released/Vendor Advisory
- https://gitlab.com/gitlab-org/gitaly/issues/1801Exploit, Issue Tracking, Vendor Advisory
- https://gitlab.com/gitlab-org/gitaly/issues/1802Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.