← back
CVE-2019-5464CWE-20

CVE-2019-5464

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 2.8%
exploitation probability
2.8%top 15% of all CVEs
observed exploitation
nono source reports it
A flawed DNS rebinding protection issue was discovered in GitLab CE/EE 10.2 and later in the `url_blocker.rb` which could result in SSRF where the library is utilized.
Affected products
GitLab · GitLab CE/EE