PT-2021-14891 · Gitlab · Gitlab
Yvvdwfon
·
Published
2021-03-24
·
Updated
2024-03-06
·
CVE-2021-22179
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
GitLab versions prior to 12.2
Description:
A vulnerability was discovered in GitLab that made it susceptible to a Server-Side Request Forgery (SSRF) attack. The attack was possible through the Outbound Requests feature.
Recommendations:
For versions prior to 12.2, update to version 12.2 or later to resolve the issue. As a temporary workaround, consider disabling the Outbound Requests feature until a patch is available. Restrict access to this feature to minimize the risk of exploitation.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gitlab