🔙 목록으로 돌아가기

CVE-2019-6793: GitLab Enterprise Edition - Server-Side Request Forgery

TitleGitLab Enterprise Edition - Server-Side Request Forgery
Authorritikchaddha
SeverityHigh
ImpactUnauthenticated attackers can exploit blind SSRF to access internal services, potentially retrieving sensitive information or performing unauthorized actions on internal systems.
RemediationUpgrade to GitLab Enterprise Edition 11.5.8, 11.6.6, 11.7.1 or later versions.
CVSS Score7.0
EPSS Score0.03925
CVE IDCVE-2019-6793
CWE IDCWE-918
Shodan Queryhtml:"GitLab Enterprise Edition"
Fofa Querybody="GitLab Enterprise Edition"
Tags cve cve2019 gitlab enterprise ssrf blind vuln

🔍 Vulnerability Description

An issue was discovered in GitLab Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The Jira integration feature is vulnerable to an unauthenticated blind SSRF issue.

🌐 HTTP Request

POST /-/jira/login/oauth/access_token HTTP/1.1
Host: d5jpidple0o48t5ap2rgom3b5i7wnj19e.oast.pro

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-6793.yaml

🦈 Packet Capture: ⬇️ Download cve-2019-6793.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A