HIGH

CVE-2020-13309

Gitlab GitLab 2020-09-14 CVSS v3.1
CVSS
8.8

Description

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was vulnerable to a blind SSRF attack through the repository mirroring feature.

Summary dbcve.org

GitLab versions before 13.1.10, 13.2.8, and 13.3.4 contain a blind Server-Side Request Forgery (SSRF) vulnerability in the repository mirroring feature. Attackers can cause the GitLab server to make HTTP requests to arbitrary internal or external URLs without receiving the response, enabling internal network reconnaissance and potential access to internal services.

Mitigation

Upgrade GitLab to version 13.1.10, 13.2.8, 13.3.4 or later. Additionally, implement network segmentation and egress filtering to limit the impact of SSRF attacks.

Weakness (CWE)

CWE-918 Server-Side Request Forgery (SSRF)

EPSS Score

1.27%
Probability of exploitation in next 30 days
68.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE