CRITICAL
CVE-2020-10980
CVSS
9.8
Description
GitLab EE/CE 8.0.rc1 to 12.9 is vulnerable to a blind SSRF in the FogBugz integration.
Summary dbcve.org
A blind Server-Side Request Forgery (SSRF) vulnerability exists in GitLab's FogBugz integration from version 8.0.rc1 through 12.9. An attacker can exploit this to make the GitLab server perform arbitrary HTTP requests to internal or external resources without proper URL validation, potentially accessing internal services, cloud metadata endpoints, or performing network reconnaissance.
Mitigation
Upgrade GitLab to version 12.10 or later. If immediate upgrade is not feasible, disable or restrict the FogBugz integration until the patch can be applied.
Weakness (CWE)
CWE-918
Server-Side Request Forgery (SSRF)
EPSS Score
1.87%
Probability of exploitation in next 30 days
78.4th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.