First published: Wed Apr 08 2020(Updated: )
GitLab EE/CE 8.0.rc1 to 12.9 is vulnerable to a blind SSRF in the FogBugz integration.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=8.0.0<=12.9 | |
GitLab | >=8.0.0<=12.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10980 is classified as a high severity vulnerability.
To fix CVE-2020-10980, upgrade GitLab to version 12.9.1 or later.
CVE-2020-10980 is a blind Server-Side Request Forgery (SSRF) vulnerability.
CVE-2020-10980 affects GitLab EE/CE versions from 8.0.rc1 to 12.9.
CVE-2020-10980 allows attackers to manipulate server requests, potentially leading to unauthorized access to internal services.