CVE-2019-13121
Description
An issue was discovered in GitLab Enterprise Edition 10.6 through 12.0.2. The GitHub project integration was vulnerable to an SSRF vulnerability which allowed an attacker to make requests to local network resources. It has Incorrect Access Control.
Summary dbcve.org
GitLab Enterprise Edition 10.6 through 12.0.2 contains an SSRF vulnerability in the GitHub project integration feature. The vulnerability allows remote attackers to make requests to internal/local network resources due to insufficient access controls on the integration, enabling potential reconnaissance and access to internal services.
Mitigation
Upgrade GitLab Enterprise Edition to a version beyond 12.0.2 that contains the security patch. Additionally, network segmentation and firewall rules can help limit the impact of SSRF attacks by restricting access to internal resources.