CRITICAL

CVE-2020-10980

Gitlab GitLab 2020-04-08 CVSS v3.1
CVSS
9.8

Description

GitLab EE/CE 8.0.rc1 to 12.9 is vulnerable to a blind SSRF in the FogBugz integration.

Summary dbcve.org

A blind Server-Side Request Forgery (SSRF) vulnerability exists in GitLab's FogBugz integration from version 8.0.rc1 through 12.9. An attacker can exploit this to make the GitLab server perform arbitrary HTTP requests to internal or external resources without proper URL validation, potentially accessing internal services, cloud metadata endpoints, or performing network reconnaissance.

Mitigation

Upgrade GitLab to version 12.10 or later. If immediate upgrade is not feasible, disable or restrict the FogBugz integration until the patch can be applied.

Weakness (CWE)

CWE-918 Server-Side Request Forgery (SSRF)

EPSS Score

1.87%
Probability of exploitation in next 30 days
78.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE