An issue exists in GitLab Enterprise Edition 10.6 up to and including 12.0.2. The GitHub project integration was vulnerable to an SSRF vulnerability which allowed an malicious user to make requests to local network resources. It has Incorrect Access Control.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
gitlab gitlab |