MEDIUM

CVE-2022-1188

Gitlab GitLab 2022-04-04 CVSS v3.1
CVSS
5.3

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 where a blind SSRF attack through the repository mirroring feature was possible.

Summary dbcve.org

A blind Server-Side Request Forgery (SSRF) vulnerability in GitLab's repository mirroring feature allows an attacker to induce the server to make arbitrary HTTP requests to internal services or external targets without seeing the response, potentially exposing internal infrastructure.

Mitigation

Upgrade GitLab to version 14.7.7, 14.9.2, or 14.8.5 or later. If immediate upgrade is not feasible, consider disabling or restricting the repository mirroring feature and implementing network segmentation to limit internal service exposure.

Weakness (CWE)

CWE-918 Server-Side Request Forgery (SSRF)

EPSS Score

1.24%
Probability of exploitation in next 30 days
67.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE