### [CVE-2019-5464](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-5464) ![](https://img.shields.io/static/v1?label=Product&message=GitLab%20CE%2FEE&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=Improper%20Input%20Validation%20(CWE-20)&color=brighgreen) ### Description A flawed DNS rebinding protection issue was discovered in GitLab CE/EE 10.2 and later in the `url_blocker.rb` which could result in SSRF where the library is utilized. ### POC #### Reference - https://gitlab.com/gitlab-org/gitlab-ce/issues/63959 - https://hackerone.com/reports/632101 #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/Ch0pin/vulnerability-review