← Volver a CVEs
CVE-2019-15728
HIGH7.5
Descripcion
An issue was discovered in GitLab Community and Enterprise Edition 10.1 through 12.2.1. Protections against SSRF attacks on the Kubernetes integration are insufficient, which could have allowed an attacker to request any local network resource accessible from the GitLab server.
Detalles CVE
Puntuacion CVSS v3.17.5
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado9/16/2019
Ultima modificacion11/21/2024
Fuentenvd
Avistamientos honeypot0
Productos afectados
gitlab:gitlab
Debilidades (CWE)
CWE-918
Referencias
https://gitlab.com/gitlab-org/gitlab-ce/issues/61314(cve@mitre.org)
https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/(af854a3a-2127-422b-91ae-364da2661108)
https://gitlab.com/gitlab-org/gitlab-ce/issues/61314(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.