HIGH

CVE-2021-22214

Gitlab GitLab 2021-06-08 CVSS v3.1
CVSS
8.6

Description

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is limited

Summary dbcve.org

This is a server-side request forgery (SSRF) vulnerability in GitLab's webhook functionality. When requests to internal networks for webhooks are enabled, an unauthenticated attacker can cause the GitLab server to make arbitrary requests to internal network resources, potentially accessing sensitive internal services.

Mitigation

Disable the 'allow requests to the internal network' setting for webhooks in GitLab settings, or upgrade to a patched GitLab version.

Weakness (CWE)

CWE-918 Server-Side Request Forgery (SSRF)

EPSS Score

27.81%
Probability of exploitation in next 30 days
98th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE