An input validation problem was discovered in the GitHub service integration which could result in an attacker being able to make arbitrary POST requests in a GitLab instance's internal network. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://hackerone.com/reports/446593 | third party advisory |
https://gitlab.com//gitlab-org/gitlab-ce/issues/54649 | vendor advisory exploit |
https://about.gitlab.com/2019/07/29/security-release-gitlab-12-dot-1-dot-2-released/ | vendor advisory |