CVE-2018-19571 is a high-severity Server-Side Request Forgery (SSRF) vulnerability affecting GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, specifically within its webhook functionality. With a CVSS score of 7.7 (High), this vulnerability allows an authenticated attacker to perform network requests from the GitLab server, potentially leading to sensitive information disclosure (C:H) with low attack complexity and no user interaction required. While not listed on the KEV catalog, exploit intelligence indicates the existence of authenticated RCE exploits for affected versions, suggesting a higher potential impact than initially assessed. The vulnerability has garnered significant community discussion and media coverage, highlighting its importance despite no direct evidence of widespread active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.18.0, < 11.3.11CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 8.18.0, < 11.3.11CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 11.4.0, < 11.4.8CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 11.4.0, < 11.4.8CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 11.5.0, < 11.5.1CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.