CVE-2022-1188
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 where a blind SSRF attack through the repository mirroring feature was possible.
Summary dbcve.org
A blind Server-Side Request Forgery (SSRF) vulnerability in GitLab's repository mirroring feature allows an attacker to induce the server to make arbitrary HTTP requests to internal services or external targets without seeing the response, potentially exposing internal infrastructure.
Mitigation
Upgrade GitLab to version 14.7.7, 14.9.2, or 14.8.5 or later. If immediate upgrade is not feasible, consider disabling or restricting the repository mirroring feature and implementing network segmentation to limit internal service exposure.