GitLab Community and Enterprise Editions version 8.3 up to 10.x before 10.3 are vulnerable to SSRF in the Services and webhooks component.
References
Link Resource
https://gitlab.com/gitlab-org/gitlab-ce/blob/master/CHANGELOG.md Release Notes Vendor Advisory
https://gitlab.com/gitlab-org/gitlab-ce/issues/41642 Issue Tracking Vendor Advisory
https://hackerone.com/reports/301924 Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2018-04-25T09:00:00

Updated: 2018-09-01T20:57:01

Reserved: 2018-03-19T00:00:00


Link: CVE-2018-8801

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-04-25T09:29:00.770

Modified: 2019-02-27T20:09:10.207


Link: CVE-2018-8801

JSON object: View

cve-icon Redhat Information

No data.

CWE