Описание
A DNS rebinding vulnerability in the Irker IRC Gateway integration in all versions of GitLab CE/EE since version 7.9 allows an attacker to trigger Server Side Request Forgery (SSRF) attacks.
Ссылки
- Third Party Advisory
- Broken LinkIssue TrackingThird Party Advisory
- Third Party Advisory
- Broken LinkIssue TrackingThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 7.9.0 (включая) до 14.7.1 (включая)Версия от 7.9.0 (включая) до 14.7.1 (включая)
Одно из
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
EPSS
Процентиль: 37%
0.00151
Низкий
5.4 Medium
CVSS3
7.6 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-918
Связанные уязвимости
CVSS3: 5.4
ubuntu
больше 3 лет назад
A DNS rebinding vulnerability in the Irker IRC Gateway integration in all versions of GitLab CE/EE since version 7.9 allows an attacker to trigger Server Side Request Forgery (SSRF) attacks.
CVSS3: 7.6
github
больше 3 лет назад
A DNS rebinding vulnerability in the Irker IRC Gateway integration in all versions of GitLab CE/EE since version 7.9 allows an attacker to trigger Server Side Request Forgery (SSRF) attacks.
EPSS
Процентиль: 37%
0.00151
Низкий
5.4 Medium
CVSS3
7.6 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-918