PT-2025-6773 · Gitlab · Gitlab Ce/Ee
Published
2025-02-12
·
Updated
2025-02-17
·
CVE-2024-9870
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GitLab EE versions 15.11 through 17.6.4
GitLab EE versions 17.7 through 17.7.3
GitLab EE versions 17.8 through 17.8.1
Description
An external service interaction issue in GitLab EE allows an attacker to send requests from the GitLab server to unintended services. This could potentially be exploited by sending malicious requests to services that are not intended to be accessed by the GitLab server.
Recommendations
For GitLab EE versions 15.11 through 17.6.4, update to version 17.6.5 or later.
For GitLab EE versions 17.7 through 17.7.3, update to version 17.7.4 or later.
For GitLab EE versions 17.8 through 17.8.1, update to version 17.8.2 or later.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gitlab Ce/Ee