Show plain JSON{"id": "CVE-2019-15728", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 5.0, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "NONE", "confidentialityImpact": "NONE"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 7.5, "attackVector": "NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "NONE"}, "impactScore": 3.6, "exploitabilityScore": 3.9}]}, "published": "2019-09-16T17:15:13.900", "references": [{"url": "https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/", "tags": ["Release Notes", "Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "https://gitlab.com/gitlab-org/gitlab-ce/issues/61314", "tags": ["Broken Link"], "source": "cve@mitre.org"}, {"url": "https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/", "tags": ["Release Notes", "Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://gitlab.com/gitlab-org/gitlab-ce/issues/61314", "tags": ["Broken Link"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-918"}]}], "descriptions": [{"lang": "en", "value": "An issue was discovered in GitLab Community and Enterprise Edition 10.1 through 12.2.1. Protections against SSRF attacks on the Kubernetes integration are insufficient, which could have allowed an attacker to request any local network resource accessible from the GitLab server."}, {"lang": "es", "value": "Se descubri\u00f3 un problema en GitLab Community and Enterprise Edition versiones 10.1 hasta 12.2.1. Las protecciones contra ataques de tipo SSRF en la integraci\u00f3n de Kubernetes son insuficientes, lo que podr\u00eda haber permitido a un atacante solicitar cualquier recurso de red local accesible desde el servidor GitLab."}], "lastModified": "2024-11-21T04:29:20.777", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*", "vulnerable": true, "matchCriteriaId": "69ED47DA-AAEA-4F30-8BED-D578600D0E96", "versionEndExcluding": "12.0.8", "versionStartIncluding": "10.1.0"}, {"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*", "vulnerable": true, "matchCriteriaId": "6B419121-58BB-44DB-BF37-F8D285F457A3", "versionEndExcluding": "12.0.8", "versionStartIncluding": "10.1.0"}, {"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*", "vulnerable": true, "matchCriteriaId": "BE0BA50B-833E-4F74-95CB-EC8963B0ABCA", "versionEndExcluding": "12.1.8", "versionStartIncluding": "12.1.0"}, {"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*", "vulnerable": true, "matchCriteriaId": "36F29405-3C84-4ECF-96B7-E25D88926B46", "versionEndExcluding": "12.1.8", "versionStartIncluding": "12.1.0"}, {"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*", "vulnerable": true, "matchCriteriaId": "16FD6BD6-8B76-4053-81C1-E9B00F279113", "versionEndExcluding": "12.2.3", "versionStartIncluding": "12.2.0"}, {"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*", "vulnerable": true, "matchCriteriaId": "F131A404-4B2B-4F77-981B-A12D8FC7F590", "versionEndExcluding": "12.2.3", "versionStartIncluding": "12.2.0"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}