HIGH

CVE-2022-0136

Gitlab GitLab 2022-03-28 CVSS v3.1
CVSS
8.1

Description

A vulnerability was discovered in GitLab versions 10.5 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1. GitLab was vulnerable to a blind SSRF attack through the Project Import feature.

Summary dbcve.org

A blind Server-Side Request Forgery (SSRF) vulnerability exists in GitLab's Project Import feature across versions 10.5 through 14.7.1. This allows an attacker to make the application perform requests to arbitrary servers, typically for internal network reconnaissance and accessing internal services that should not be exposed.

Mitigation

Upgrade GitLab to version 14.7.2 or later. Additionally, enforce strict network segmentation and firewall rules to limit the impact of SSRF by restricting outbound connections from the GitLab server to internal infrastructure.

Weakness (CWE)

CWE-918 Server-Side Request Forgery (SSRF)

EPSS Score

0.86%
Probability of exploitation in next 30 days
57th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE