CVE-2019-6781

HIGH

GitLab 11.5.0-11.5.7, 11.6.0-11.6.5, 11.7.0 - Open Redirect via Profile Name in Notification Emails

Title source: llm
STIX 2.1

Description

An Improper Input Validation issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It was possible to use the profile name to inject a potentially malicious link into notification emails.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
https://gitlab.com/gitlab-org/gitlab-ce/issues/22076

Scores

CVSS v3 7.5
EPSS 0.0011
EPSS Percentile 29.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-601
Status published
Products (1)
gitlab/gitlab 11.5.0 - 11.5.10 (2 CPE variants)
Published May 17, 2019
Tracked Since Feb 18, 2026