CRITICAL
A vulnerability was discovered in GitLab starting with version 12
Published Mar 28, 2022
9.1
CRITICALCVSS 3.1
EPSS 1.27%
Description
A vulnerability was discovered in GitLab starting with version 12. GitLab was vulnerable to a blind SSRF attack since requests to shared address space were not blocked.
Affected products
-
- Version >=12.0, <14.5.4StatusaffectedConstraints-
- Version >=14.6, <14.6.4StatusaffectedConstraints-
- Version >=14.7, <14.7.1StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0249.json x_refsource_CONFIRMVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/29395 x_refsource_MISCExploitIssue TrackingVendor Advisory
- https://hackerone.com/reports/579934 x_refsource_MISCPermissions RequiredThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0249.json | x_refsource_CONFIRMVendor Advisory | |
| https://gitlab.com/gitlab-org/gitlab/-/issues/29395 | x_refsource_MISCExploitIssue TrackingVendor Advisory | |
| https://hackerone.com/reports/579934 | x_refsource_MISCPermissions RequiredThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Mar 28, 2022
Updated Aug 2, 2024
Reserved Jan 17, 2022
Link CVE-2022-0249
CISA Vulnrichment
Updated n/a