MEDIUM

CVE-2021-39894

Gitlab GitLab 2021-10-05 CVSS v3.1
CVSS
5.4

Description

In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vulnerability exists in Fogbugz importer which may be used by attackers to exploit Server Side Request Forgery attacks.

Summary dbcve.org

A DNS rebinding vulnerability exists in GitLab's Fogbugz importer across all versions since 8.0. Attackers can exploit this to perform Server Side Request Forgery (SSRF) attacks by manipulating DNS resolution to bypass security controls and make the server request arbitrary URLs.

Mitigation

Update GitLab to the latest patched version. If the Fogbugz importer is not needed, disable it as a precautionary measure.

Weakness (CWE)

CWE-918 Server-Side Request Forgery (SSRF)

EPSS Score

0.61%
Probability of exploitation in next 30 days
48th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE