CRITICAL

CVE-2020-10956

Gitlab GitLab 2020-03-27 CVSS v3.1
CVSS
9.8

Description

GitLab 8.10 and later through 12.9 is vulnerable to an SSRF in a project import note feature.

Summary dbcve.org

GitLab versions 8.10 through 12.9 contain a Server-Side Request Forgery (SSRF) vulnerability in the project import note feature. This allows an attacker to make the GitLab server perform arbitrary requests to internal or external resources by manipulating the import note functionality.

Mitigation

Upgrade GitLab to version 12.9.1 or later, which contains the patched version of the affected component.

Weakness (CWE)

CWE-918 Server-Side Request Forgery (SSRF)

EPSS Score

1.45%
Probability of exploitation in next 30 days
72.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE