CVE-2020-10077: SSRF
Published Mar 13, 2020
·Updated
GitLab EE 3.0 through 12.8.1 allows SSRF. An internal investigation revealed that a particular deprecated service was creating a server side request forgery risk.
Affected Software
1 affected component
GitLab GitLab>=3.0.0<=12.8.1
Event History
Mar 13, 2020
CVE Published
via MITRE·05:01 PM
Data Sourced
via MITRE·05:01 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-10077?
CVE-2020-10077 is classified as a medium severity vulnerability due to its potential to cause server-side request forgery.
2
How do I fix CVE-2020-10077?
To mitigate CVE-2020-10077, upgrade to a version of GitLab EE that is higher than 12.8.1.
3
What versions of GitLab EE are affected by CVE-2020-10077?
CVE-2020-10077 affects GitLab EE versions from 3.0.0 through 12.8.1.
4
Is there a workaround for CVE-2020-10077?
There is no specific workaround for CVE-2020-10077; upgrading is the recommended action.
5
What type of vulnerability is CVE-2020-10077?
CVE-2020-10077 is a server-side request forgery (SSRF) vulnerability.