PT-2021-14890 · Gitlab · Gitlab

Yvvdwfon

·

Published

2021-03-24

·

Updated

2024-03-06

·

CVE-2021-22178

CVSS v3.1

5.0

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: GitLab versions 13.2 and later
Description: An issue has been discovered in GitLab, making it vulnerable to a Server-Side Request Forgery (SRRF) attack through the Prometheus integration.
Recommendations: For GitLab versions 13.2 and later, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SSRF

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2021-22178
CVE-2021-22178

Affected Products

Gitlab