Back to search
CVE-2019-5464
Published: Jan 28, 2020
Modified: Aug 4, 2024
PUBLISHED
Description
A flawed DNS rebinding protection issue was discovered in GitLab CE/EE 10.2 and later in the `url_blocker.rb` which could result in SSRF where the library is utilized.
| Vendor | Product | Versions |
|---|---|---|
GitLab | GitLab CE/EE | affected Affects GitLab CE/EE 10.2 and lateraffected Fixed in 12.1.2 in 12.0.4 and in 11.11.6 |
Weaknesses (CWE)
References
https://hackerone.com/reports/632101
x_refsource_MISC
https://gitlab.com/gitlab-org/gitlab-ce/issues/63959
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now