HIGH
CVE-2022-0136
CVSS
8.1
Description
A vulnerability was discovered in GitLab versions 10.5 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1. GitLab was vulnerable to a blind SSRF attack through the Project Import feature.
Summary dbcve.org
A blind Server-Side Request Forgery (SSRF) vulnerability exists in GitLab's Project Import feature across versions 10.5 through 14.7.1. This allows an attacker to make the application perform requests to arbitrary servers, typically for internal network reconnaissance and accessing internal services that should not be exposed.
Mitigation
Upgrade GitLab to version 14.7.2 or later. Additionally, enforce strict network segmentation and firewall rules to limit the impact of SSRF by restricting outbound connections from the GitLab server to internal infrastructure.
Weakness (CWE)
CWE-918
Server-Side Request Forgery (SSRF)
EPSS Score
0.86%
Probability of exploitation in next 30 days
57th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.