CVE-2019-14944

MEDIUM

GitLab < 11.11.8, 12 < 12.0.6, 12.1 < 12.1.6 - Command Injection via Gitaly Command-Line Flags

Title source: llm
STIX 2.1

Description

An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Gitaly allows injection of command-line flags. This sometimes leads to privilege escalation or remote code execution.

Scores

CVSS v3 6.5
EPSS 0.0899
EPSS Percentile 92.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-77
Status published
Products (1)
gitlab/gitlab < 11.11.8 (2 CPE variants)
Published Apr 16, 2023
Tracked Since Feb 18, 2026