HIGH
Server-Side Request Forgery (SSRF) in GitLab
Published Sep 12, 2024
7.7
HIGHCVSS 3.1
EPSS 0.56%
Description
A server-side request forgery issue has been discovered in GitLab EE affecting all versions starting from 16.8 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. It was possible for an attacker to make requests to internal resources using a custom Maven Dependency Proxy URL
Affected products
-
Affected
- ≥ 16.8, < 17.1.7
- ≥ 17.2, < 17.2.5
- ≥ 17.3, < 17.3.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to version 17.1.7, 17.2.5 or 17.3.2
Weaknesses (1)
References (3)
- https://about.gitlab.com/releases/2024/09/11/patch-release-gitlab-17-3-2-released/
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-49313 Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/455273 issue-trackingpermissions-requiredBroken Link
| Link | Providers | Tags |
|---|---|---|
| https://about.gitlab.com/releases/2024/09/11/patch-release-gitlab-17-3-2-released/ | ||
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-49313 | Advisory | |
| https://gitlab.com/gitlab-org/gitlab/-/issues/455273 | issue-trackingpermissions-requiredBroken Link |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Sep 12, 2024
Updated Sep 13, 2024
Reserved Sep 9, 2024
Link CVE-2024-8635
CISA Vulnrichment
Updated Sep 12, 2024
Red Hat
No data
GitHub
No data