CVE-2019-6793: SSRF
Published Sep 9, 2019
·Updated
An issue was discovered in GitLab Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The Jira integration feature is vulnerable to an unauthenticated blind SSRF issue.
Affected Software
3 affected components
GitLab GitLab>=10.0.0<11.5.8
GitLab GitLab>=11.6.0<11.6.6
GitLab GitLab>=11.7.0<11.7.1
Event History
Sep 9, 2019
CVE Published
via MITRE·07:39 PM
Data Sourced
via MITRE·07:39 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-6793?
CVE-2019-6793 is considered to have a medium severity due to its potential for unauthenticated blind SSRF attacks.
2
How do I fix CVE-2019-6793?
To fix CVE-2019-6793, upgrade GitLab Enterprise Edition to versions 11.5.8, 11.6.6, or 11.7.1 or later.
3
What versions of GitLab are affected by CVE-2019-6793?
CVE-2019-6793 affects GitLab Enterprise Edition versions before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1.
4
What type of vulnerability is CVE-2019-6793?
CVE-2019-6793 is classified as an unauthenticated blind Server-Side Request Forgery (SSRF) vulnerability.
5
Can CVE-2019-6793 be exploited remotely?
Yes, CVE-2019-6793 can be exploited remotely due to the unauthenticated nature of the SSRF attack.