High severity7.5NVD Advisory· Published May 17, 2019· Updated Jun 17, 2026
CVE-2019-6781
CVE-2019-6781
Description
An Improper Input Validation issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It was possible to use the profile name to inject a potentially malicious link into notification emails.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- GitLab/GitLab Community and Enterprise Editiondescription
- Range: <11.5.8, 11.6.x <11.6.6, 11.7.x <11.7.1
<11.5.8, 11.6.x <11.6.6, 11.7.x <11.7.1+ 2 more
- (no CPE)range: <11.5.8, 11.6.x <11.6.6, 11.7.x <11.7.1
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=11.5.0,<11.5.10
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=11.5.0,<11.5.10
Patches
Vulnerability mechanics
References
2- about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/nvdRelease NotesVendor Advisory
- gitlab.com/gitlab-org/gitlab-ce/issues/22076nvdVendor Advisory
News mentions
0No linked articles in our index yet.