CVE-2018-20497
Published: 30 December 2019
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows SSRF.
Notes
Author | Note |
---|---|
msalvatore | Affects GitLab CE/EE 8.7.0 and later. |
Priority
Severity score breakdown
Parameter | Value |
---|---|
Base score | 5.0 |
Attack vector | Network |
Attack complexity | Low |
Privileges required | Low |
User interaction | None |
Scope | Changed |
Confidentiality | Low |
Integrity impact | None |
Availability impact | None |
Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N |