CVE-2019-6793 Information

Description

An issue was discovered in GitLab Enterprise Edition before 11.5.8 11.6.x before 11.6.6 and 11.7.x before 11.7.1. The Jira integration feature is vulnerable to an unauthenticated blind SSRF issue.

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L

Reference

https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/ https://gitlab.com/gitlab-org/gitlab-ce/issues/50748

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

LOW

Availability Impact

HIGH

Base Score

LOW

Base Severity

7.0

Share on: