HIGH

CVE-2019-13121

Gitlab GitLab 2020-03-10 CVSS v3.1
CVSS
7.5

Description

An issue was discovered in GitLab Enterprise Edition 10.6 through 12.0.2. The GitHub project integration was vulnerable to an SSRF vulnerability which allowed an attacker to make requests to local network resources. It has Incorrect Access Control.

Summary dbcve.org

GitLab Enterprise Edition 10.6 through 12.0.2 contains an SSRF vulnerability in the GitHub project integration feature. The vulnerability allows remote attackers to make requests to internal/local network resources due to insufficient access controls on the integration, enabling potential reconnaissance and access to internal services.

Mitigation

Upgrade GitLab Enterprise Edition to a version beyond 12.0.2 that contains the security patch. Additionally, network segmentation and firewall rules can help limit the impact of SSRF attacks by restricting access to internal resources.

Weakness (CWE)

CWE-918 Server-Side Request Forgery (SSRF)

EPSS Score

0.9%
Probability of exploitation in next 30 days
58.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE