Vulnerabilities > CVE-2020-13286 - Server-Side Request Forgery (SSRF) vulnerability in Gitlab

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
LOW
Availability impact
NONE
network
low complexity
gitlab
CWE-918

Summary

For GitLab before 13.0.12, 13.1.6, 13.2.3 user controlled git configuration settings can be modified to result in Server Side Request Forgery.

Common Weakness Enumeration (CWE)