Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Pedro Pombeiro

#52692de 53,635
3.5CVSS total
Vulnerabilidades · 1
PT-2023-14062
3.5
2023-01-27
Gitlab · Gitlab Ce/Ee · CVE-2022-4201
**Name of the Vulnerable Software and Affected Versions** GitLab CE/EE versions 11.3 through 15.4.5 GitLab CE/EE versions 15.5 through 15.5.4 GitLab CE/EE versions 15.6 through 15.6.0 **Description** A blind Server-Side Request Forgery (SSRF) issue allows an attacker to connect to local addresses when configuring a malicious GitLab Runner. This can be exploited when an attacker has the ability to configure a GitLab Runner. **Recommendations** For GitLab CE/EE versions 11.3 through 15.4.5, update to version 15.4.6 or later. For GitLab CE/EE versions 15.5 through 15.5.4, update to version 15.5.5 or later. For GitLab CE/EE versions 15.6 through 15.6.0, update to version 15.6.1 or later.