An issue was discovered in GitLab Enterprise Edition 10.6 through 12.0.2. The GitHub project integration was vulnerable to an SSRF vulnerability which allowed an attacker to make requests to local network resources. It has Incorrect Access Control.
References
Link | Resource |
---|---|
https://about.gitlab.com/blog/categories/releases/ | Release Notes Vendor Advisory |
https://about.gitlab.com/releases/2019/07/03/security-release-gitlab-12-dot-0-dot-3-released/ | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2020-03-10T17:11:26
Updated: 2020-03-10T17:11:26
Reserved: 2019-07-01T00:00:00
Link: CVE-2019-13121
JSON object: View
NVD Information
Status : Analyzed
Published: 2020-03-10T18:15:11.623
Modified: 2020-03-11T20:36:20.160
Link: CVE-2019-13121
JSON object: View
Redhat Information
No data.
CWE