HIGH
CVE-2021-22214
CVSS
8.6
Description
When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is limited
Summary dbcve.org
This is a server-side request forgery (SSRF) vulnerability in GitLab's webhook functionality. When requests to internal networks for webhooks are enabled, an unauthenticated attacker can cause the GitLab server to make arbitrary requests to internal network resources, potentially accessing sensitive internal services.
Mitigation
Disable the 'allow requests to the internal network' setting for webhooks in GitLab settings, or upgrade to a patched GitLab version.
Weakness (CWE)
CWE-918
Server-Side Request Forgery (SSRF)
EPSS Score
27.81%
Probability of exploitation in next 30 days
98th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.