CVE-2019-5461 is an input validation vulnerability in the GitHub service integration of GitLab, affecting versions prior to 12.1.2, 12.0.4, and 11.11.6. An attacker could exploit this flaw to make arbitrary POST requests within a GitLab instance's internal network. The vulnerability has a low CVSS score of 3.5, indicating a low severity with an adjacent attack vector, low complexity, and limited impact (integrity). There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, though it was addressed in GitLab security releases.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 11.11.0, < 11.11.7CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 11.11.0, < 11.11.7CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 12.0.0, < 12.0.4CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 12.0.0, < 12.0.4CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 12.1.0, < 12.1.2CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.