PT-2024-6938 · Gitlab · Gitlab Ce/Ee+1

Joaxcaron

·

Published

2024-10-09

·

Updated

2024-10-16

·

CVE-2024-8977

CVSS v3.1

8.2

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions GitLab EE versions 15.10 through 17.2.8 GitLab EE versions 17.3 through 17.3.4 GitLab EE versions 17.4 through 17.4.1
Description An issue has been discovered in GitLab EE that could allow a remote attacker to perform a Server-Side Request Forgery (SSRF) attack. This issue is related to insufficient validation of incoming requests. Instances with the Product Analytics Dashboard configured and enabled are vulnerable to SSRF attacks.
Recommendations For GitLab EE versions 15.10 through 17.2.8, upgrade to version 17.2.9. For GitLab EE versions 17.3 through 17.3.4, upgrade to version 17.3.5. For GitLab EE versions 17.4 through 17.4.1, upgrade to version 17.4.2. As a temporary workaround, consider disabling the Product Analytics Dashboard until a patch is available. Restrict access to the Product Analytics Dashboard to minimize the risk of exploitation.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

BDU:2024-08161
BIT-GITLAB-2024-8977
CVE-2024-8977

Affected Products

Gitlab
Gitlab Ce/Ee