HIGH

CVE-2019-19261

Gitlab GitLab 2020-01-03 CVSS v3.1
CVSS
8.8

Description

GitLab Enterprise Edition (EE) 6.7 and later through 12.5 allows SSRF.

Summary dbcve.org

Server-Side Request Forgery (SSRF) vulnerability in GitLab Enterprise Edition allowing remote attackers to make the server perform requests to arbitrary internal or external resources. Affects versions 6.7 through 12.5.

Mitigation

Upgrade GitLab EE to version 12.6 or later which contains the security patch. For systems that cannot be immediately upgraded, implement network segmentation and restrict outbound access from the GitLab server.

Weakness (CWE)

CWE-918 Server-Side Request Forgery (SSRF)

EPSS Score

1.02%
Probability of exploitation in next 30 days
61.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE