CRITICAL
CVE-2020-10956
CVSS
9.8
Description
GitLab 8.10 and later through 12.9 is vulnerable to an SSRF in a project import note feature.
Summary dbcve.org
GitLab versions 8.10 through 12.9 contain a Server-Side Request Forgery (SSRF) vulnerability in the project import note feature. This allows an attacker to make the GitLab server perform arbitrary requests to internal or external resources by manipulating the import note functionality.
Mitigation
Upgrade GitLab to version 12.9.1 or later, which contains the patched version of the affected component.
Weakness (CWE)
CWE-918
Server-Side Request Forgery (SSRF)
EPSS Score
1.45%
Probability of exploitation in next 30 days
72.2th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.