MEDIUM

CVE-2021-22179

Gitlab GitLab 2021-03-24 CVSS v3.1
CVSS
5.4

Description

A vulnerability was discovered in GitLab versions before 12.2. GitLab was vulnerable to a SSRF attack through the Outbound Requests feature.

Summary dbcve.org

GitLab versions before 12.2 contained a Server-Side Request Forgery (SSRF) vulnerability in the Outbound Requests feature. This allowed attackers to cause the GitLab server to make requests to internal services or arbitrary URLs, potentially exposing internal infrastructure.

Mitigation

Upgrade GitLab to version 12.2 or later to patch the SSRF vulnerability in the Outbound Requests feature.

Weakness (CWE)

CWE-918 Server-Side Request Forgery (SSRF)

EPSS Score

0.95%
Probability of exploitation in next 30 days
59.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE