CRITICAL

CVE-2019-12443

Gitlab GitLab 2020-03-10 CVSS v3.1
CVSS
9.8

Description

An issue was discovered in GitLab Community and Enterprise Edition 10.2 through 11.11. Multiple features contained Server-Side Request Forgery (SSRF) vulnerabilities caused by an insufficient validation to prevent DNS rebinding attacks.

Summary dbcve.org

Multiple GitLab features contained SSRF vulnerabilities due to insufficient validation to prevent DNS rebinding attacks, allowing attackers to make the server perform requests to arbitrary URLs (including internal services).

Mitigation

Upgrade GitLab to version 11.11.1 or later; implement allowlist validation for URLs and DNS rebinding protection in any custom integrations connecting to external resources.

Weakness (CWE)

CWE-918 Server-Side Request Forgery (SSRF)

EPSS Score

1.21%
Probability of exploitation in next 30 days
67.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE