HIGH

CVE-2021-39935

Gitlab GitLab 2021-12-13 CVSS v3.1
CVSS
7.5
KEV

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Unauthorized external users could perform Server Side Requests via the CI Lint API

Summary dbcve.org

This is a Server-Side Request Forgery (SSRF) vulnerability in GitLab CE/EE affecting the CI Lint API. Unauthorized external users can exploit the CI Lint API endpoint to have the GitLab server make requests to internal resources or external services, potentially bypassing network boundaries.

Mitigation

Upgrade GitLab to version 14.3.6, 14.4.4, 14.5.2 or later. These versions contain the fix that properly authorizes and validates requests through the CI Lint API endpoint.

Weakness (CWE)

CWE-918 Server-Side Request Forgery (SSRF)

EPSS Score

35.65%
Probability of exploitation in next 30 days
98.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE