CVE-2019-15728

NameCVE-2019-15728
DescriptionAn issue was discovered in GitLab Community and Enterprise Edition 10.1 through 12.2.1. Protections against SSRF attacks on the Kubernetes integration are insufficient, which could have allowed an attacker to request any local network resource accessible from the GitLab server.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
gitlabsourceexperimental12.0.8-1
gitlabsource(unstable)12.6.8-3

Notes

https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/

Search for package or bug name: Reporting problems