PT-2024-7878 · Gitlab · Gitlab Ce/Ee+1

Joernchen

·

Published

2024-02-13

·

Updated

2024-09-14

·

CVE-2024-8635

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GitLab Enterprise Edition versions 16.8 through 17.1.7 GitLab Enterprise Edition versions 17.2 through 17.2.5 GitLab Enterprise Edition versions 17.3 through 17.3.2
Description The issue is related to insufficient server-side request validation, allowing an attacker to perform Server-Side Request Forgery (SSRF) attacks using a custom Maven Dependency Proxy URL. This enables the attacker to make requests to internal resources.
Recommendations For GitLab Enterprise Edition versions 16.8 through 17.1.7, update to version 17.1.7 or later. For GitLab Enterprise Edition versions 17.2 through 17.2.5, update to version 17.2.5 or later. For GitLab Enterprise Edition versions 17.3 through 17.3.2, update to version 17.3.2 or later. As a temporary workaround, consider restricting access to the Maven Dependency Proxy URL to minimize the risk of exploitation.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

BDU:2024-09381
BIT-GITLAB-2024-8635
CVE-2024-8635

Affected Products

Gitlab
Gitlab Ce/Ee