Medium severity5.4NVD Advisory· Published Jan 3, 2020· Updated Jun 17, 2026
CVE-2019-19311
CVE-2019-19311
Description
GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 allows XSS in group and profile fields.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*+ 1 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=8.14.0,<12.3.7
- (no CPE)range: 8.14 through 12.5, 12.4.3, and 12.3.6
- GitLab/GitLab EEdescription
- Range: 8.14 through 12.5, 12.4.3, and 12.3.6
Patches
Vulnerability mechanics
References
3- about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/nvdRelease NotesVendor Advisory
- about.gitlab.com/blog/categories/releases/nvdRelease NotesVendor Advisory
- gitlab.com/gitlab-org/gitlab/issues/31536nvdBroken LinkVendor Advisory
News mentions
0No linked articles in our index yet.