GitLab EE Vulnerable to SSRF Attacks
CVE-2024-8977
Key Information:
Badges
Summary
A vulnerability exists in GitLab EE that affects specific versions of the software, particularly those with the Product Analytics Dashboard enabled. This flaw exposes instances to Server-Side Request Forgery (SSRF) attacks, potentially allowing an attacker to manipulate server requests to internal systems, leading to unauthorized access or data leakage. Updates are recommended for all affected versions to enhance security and mitigate risks associated with this vulnerability.
Affected Version(s)
GitLab 15.10 < 17.2.9
GitLab 17.3 < 17.3.5
GitLab 17.4 < 17.4.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved