PT-2025-6773 · Gitlab · Gitlab Ce/Ee

Published

2025-02-12

·

Updated

2025-02-17

·

CVE-2024-9870

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GitLab EE versions 15.11 through 17.6.4 GitLab EE versions 17.7 through 17.7.3 GitLab EE versions 17.8 through 17.8.1
Description An external service interaction issue in GitLab EE allows an attacker to send requests from the GitLab server to unintended services. This could potentially be exploited by sending malicious requests to services that are not intended to be accessed by the GitLab server.
Recommendations For GitLab EE versions 15.11 through 17.6.4, update to version 17.6.5 or later. For GitLab EE versions 17.7 through 17.7.3, update to version 17.7.4 or later. For GitLab EE versions 17.8 through 17.8.1, update to version 17.8.2 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-02775
BIT-GITLAB-2024-9870
CVE-2024-9870

Affected Products

Gitlab Ce/Ee