VYPR
Unrated severityNVD Advisory· Published Mar 13, 2020· Updated Aug 4, 2024

CVE-2020-10077

CVE-2020-10077

Description

GitLab EE 3.0 through 12.8.1 allows SSRF. An internal investigation revealed that a particular deprecated service was creating a server side request forgery risk.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

GitLab EE 3.0–12.8.1 vulnerable to SSRF via a deprecated service, enabling internal network probing.

Vulnerability

GitLab EE versions 3.0 through 12.8.1 contain a server-side request forgery (SSRF) vulnerability. An internal investigation revealed that a particular deprecated service was creating a request forgery risk [1]. The vulnerability allows an attacker to craft requests that cause the server to make unintended requests to internal or external systems.

Exploitation

An attacker can exploit this SSRF by sending specially crafted requests to the GitLab instance that leverage the deprecated service. No authentication is required, but the attacker must be able to interact with the GitLab EE instance over the network. The exact attack vector involves triggering the deprecated service to initiate requests to arbitrary destinations.

Impact

Successful exploitation allows an attacker to probe internal network resources, including services not directly accessible from the internet. This can lead to information disclosure, such as internal IP addresses, service banners, or sensitive data, and may serve as a stepping stone for further attacks.

Mitigation

GitLab has addressed this vulnerability in version 12.8.2, released on March 4, 2020 [1]. Users running GitLab EE 12.8.1 or earlier should upgrade to 12.8.2 or later. There are no known workarounds for unpatched versions.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.