HIGH
CVE-2021-39867
CVSS
8.1
Description
In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks.
Summary dbcve.org
A DNS rebinding vulnerability in the Gitea Importer component of GitLab allows attackers to bypass host-based restrictions by exploiting the timing gap between DNS resolution and HTTP requests, enabling SSRF attacks against internal services.
Mitigation
Implement DNS rebinding protections in the Gitea Importer, including strict host allowlisting, DNS cache disabling, and request timeout controls to prevent attackers from directing the server to internal or unauthorized endpoints.
Weakness (CWE)
CWE-918
Server-Side Request Forgery (SSRF)
EPSS Score
0.89%
Probability of exploitation in next 30 days
57.9th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.