CVE-2019-15728: SSRF
An issue was discovered in GitLab Community and Enterprise Edition 10.1 through 12.2.1. Protections against SSRF attacks on the Kubernetes integration are insufficient, which could have allowed an attacker to request any local network resource accessible from the GitLab server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-15728?
CVE-2019-15728 is rated as a high severity vulnerability due to its potential for SSRF attacks allowing access to local network resources.
How do I fix CVE-2019-15728?
To fix CVE-2019-15728, update your GitLab instance to version 12.2.3 or later.
Which versions of GitLab are affected by CVE-2019-15728?
CVE-2019-15728 affects GitLab Community and Enterprise Editions from version 10.1.0 to 12.2.1.
What types of attacks does CVE-2019-15728 allow?
CVE-2019-15728 allows attackers to execute SSRF (Server-Side Request Forgery) attacks targeting any local network resources accessible from the GitLab server.
Is CVE-2019-15728 present in GitLab versions after 12.2.1?
No, CVE-2019-15728 has been resolved in GitLab versions released after 12.2.1.