HIGH

CVE-2021-39867

Gitlab GitLab 2021-10-05 CVSS v3.1
CVSS
8.1

Description

In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks.

Summary dbcve.org

A DNS rebinding vulnerability in the Gitea Importer component of GitLab allows attackers to bypass host-based restrictions by exploiting the timing gap between DNS resolution and HTTP requests, enabling SSRF attacks against internal services.

Mitigation

Implement DNS rebinding protections in the Gitea Importer, including strict host allowlisting, DNS cache disabling, and request timeout controls to prevent attackers from directing the server to internal or unauthorized endpoints.

Weakness (CWE)

CWE-918 Server-Side Request Forgery (SSRF)

EPSS Score

0.89%
Probability of exploitation in next 30 days
57.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE