HIGH

CVE-2024-8977

Gitlab GitLab 2024-10-10 CVSS v3.1
CVSS
8.1

Description

An issue has been discovered in GitLab EE affecting all versions starting from 15.10 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior to 17.4.2. Instances with Product Analytics Dashboard configured and enabled could be vulnerable to SSRF attacks.

Summary dbcve.org

Server-Side Request Forgery (SSRF) vulnerability in GitLab EE allows attackers to make the server perform unintended requests to internal or external resources. The flaw exists in the Product Analytics Dashboard feature when configured and enabled, potentially exposing internal services and infrastructure.

Mitigation

Upgrade GitLab to version 17.2.9, 17.3.5, or 17.4.2 or later. Until patching is feasible, consider disabling the Product Analytics Dashboard feature as a temporary workaround.

Weakness (CWE)

CWE-918 Server-Side Request Forgery (SSRF)

EPSS Score

0.55%
Probability of exploitation in next 30 days
45th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE