CVE-2018-17452: SSRF
An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Side Request Forgery (SSRF) via a loopback address to the validatelocalhost function in urlblocker.rb.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-17452?
CVE-2018-17452 is considered a high severity vulnerability due to its potential for Server-Side Request Forgery (SSRF).
How do I fix CVE-2018-17452?
To fix CVE-2018-17452, upgrade GitLab to version 11.1.7, 11.2.4, or 11.3.1 or later.
Which versions of GitLab are affected by CVE-2018-17452?
CVE-2018-17452 affects GitLab Community and Enterprise Editions before version 11.1.7, between 11.2.0 and 11.2.4, and exactly version 11.3.0.
What type of vulnerability is CVE-2018-17452?
CVE-2018-17452 is classified as a Server-Side Request Forgery (SSRF) vulnerability.
What is the impact of exploiting CVE-2018-17452?
Exploiting CVE-2018-17452 can allow attackers to perform unauthorized requests to internal services of the server.