CVE-2018-20499 describes a Server-Side Request Forgery (SSRF) vulnerability affecting GitLab Community and Enterprise Editions across several versions prior to 11.4.13, 11.5.6, and 11.6.1. This high-severity flaw, with a CVSS score of 7.2, allows an unauthenticated attacker to initiate requests from the GitLab server to internal or external resources, potentially leading to information disclosure or limited system compromise. While no public exploit code or active exploitation has been observed, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 11.0.0, < 11.4.13CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 11.0.0, < 11.4.13CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 11.5.0, < 11.5.6CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 11.5.0, < 11.5.6CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 11.6.0, < 11.6.1CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.