HIGH
CVE-2019-19261
CVSS
8.8
Description
GitLab Enterprise Edition (EE) 6.7 and later through 12.5 allows SSRF.
Summary dbcve.org
Server-Side Request Forgery (SSRF) vulnerability in GitLab Enterprise Edition allowing remote attackers to make the server perform requests to arbitrary internal or external resources. Affects versions 6.7 through 12.5.
Mitigation
Upgrade GitLab EE to version 12.6 or later which contains the security patch. For systems that cannot be immediately upgraded, implement network segmentation and restrict outbound access from the GitLab server.
Weakness (CWE)
CWE-918
Server-Side Request Forgery (SSRF)
EPSS Score
1.02%
Probability of exploitation in next 30 days
61.8th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.