6.5
CVSSv3

CVE-2018-8801

Published: 25/04/2018 Updated: 27/02/2019
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

GitLab Community and Enterprise Editions version 8.3 up to 10.x prior to 10.3 are vulnerable to SSRF in the Services and webhooks component.

Vulnerable Product Search on Vulmon Subscribe to Product

gitlab gitlab

Vendor Advisories

Debian Bug report logs - #893905 gitlab: CVE-2018-8801 CVE-2018-8971 Package: gitlab; Maintainer for gitlab is Debian Ruby Extras Maintainers <pkg-ruby-extras-maintainers@listsaliothdebianorg>; Source for gitlab is src:gitlab (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Fri, 23 Mar ...