CVE-2019-15726

MEDIUM

GitLab < 12.2.1 - Information Disclosure via Markdown Embedded Media

Title source: llm
STIX 2.1

Description

An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Embedded images and media files in markdown could be pointed to an arbitrary server, which would reveal the IP address of clients requesting the file from that server.

References (2)

Core 2
Core References

Scores

CVSS v3 5.3
EPSS 0.0026
EPSS Percentile 49.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

Status published
Products (1)
gitlab/gitlab < 12.0.8 (2 CPE variants)
Published Sep 16, 2019
Tracked Since Feb 18, 2026