CRITICAL
CVE-2021-22175
CVSS
9.8
KEV
Description
When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is disabled
Summary dbcve.org
A server-side request forgery (SSRF) vulnerability in GitLab allows unauthenticated attackers to make the GitLab server execute arbitrary HTTP requests to internal network resources when webhook functionality permits internal network access. This affects all versions since 10.5 and can be exploited even on instances with registration disabled.
Mitigation
Upgrade GitLab to the patched version and/or disable the ability for webhooks to make requests to internal network addresses.
Weakness (CWE)
CWE-918
Server-Side Request Forgery (SSRF)
EPSS Score
53.37%
Probability of exploitation in next 30 days
98.9th percentile
References
https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22175.json
Vendor Advisory
https://gitlab.com/gitlab-org/gitlab/-/issues/294178
Exploit, Issue Tracking, Vendor Advisory
https://hackerone.com/reports/1059596
Permissions Required, Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22175
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.