CVE-2019-5468 describes a privilege escalation vulnerability in GitLab versions prior to 12.1.2, 12.0.4, and 11.11.6, specifically when Mattermost slash commands are utilized by a blocked account. This high-severity flaw (CVSS 8.8) has a low attack complexity and could lead to significant impacts on confidentiality, integrity, and availability. While no active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB) has been identified, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the cybersecurity landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 11.11.0, < 11.11.6CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 11.11.0, < 11.11.6CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 12.0.0, < 12.0.4CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 12.0.0, < 12.0.4CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 12.1.0, < 12.1.2CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.