Description
GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an SSRF vulnerability in webhooks.
Exploits (5)
References (4)
Scores
CVSS v3
7.7
EPSS
0.3531
EPSS Percentile
97.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Lab Environment
Details
CWE
CWE-918
Status
published
Products (1)
gitlab/gitlab
8.18.0 - 11.3.11 (2 CPE variants)
Published
Jul 10, 2019
Tracked Since
Feb 18, 2026