{"id":"CVE-2019-19628","details":"In GitLab EE 11.3 through 12.5.3, 12.4.5, and 12.3.8, insufficient parameter sanitization for the Maven package registry could lead to privilege escalation and remote code execution vulnerabilities under certain conditions.","modified":"2026-08-27T18:53:18.068223Z","published":"2020-01-05T22:15:11.173Z","references":[{"type":"ADVISORY","url":"https://about.gitlab.com/blog/2019/12/10/critical-security-release-gitlab-12-5-4-released/"},{"type":"ADVISORY","url":"https://about.gitlab.com/blog/categories/releases/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.com/gitlab-org/gitlab","events":[{"introduced":"1bbe39452664021af90851aef8527ce5e850343e"},{"last_affected":"5b6250ce868e5e25ff15d67f9002c357ae4f5b17"},{"introduced":"572e09f5e8fcd54b0366836668e6685da68de22f"},{"last_affected":"4025dea89989ebe3bb6dcc8d5d9ddf9015cd868f"},{"introduced":"4878f9ac8941c5ad124c9f2216897109c5dde4af"},{"last_affected":"6395589327610e6fa37aa26115be8040b0c25a6b"}],"database_specific":{"cpe":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","extracted_events":[{"introduced":"11.3.0"},{"last_affected":"12.3.8"},{"introduced":"12.4.0"},{"last_affected":"12.4.5"},{"introduced":"12.5.0"},{"last_affected":"12.5.3"}],"source":"CPE_RANGE"}}],"versions":["v12.5.3-ee","v12.4.5-ee","v12.5.0-ee","v12.4.3-ee","v12.4.2-ee","v12.4.0-ee"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-19628.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}