An issue has been discovered in GitLab EE affecting all versions starting from 15.10 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior to 17.4.2. Instances with Product Analytics Dashboard configured and enabled could be vulnerable to SSRF attacks.
History

Wed, 16 Oct 2024 17:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

Thu, 10 Oct 2024 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Oct 2024 10:15:00 +0000

Type Values Removed Values Added
Description An issue has been discovered in GitLab EE affecting all versions starting from 15.10 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior to 17.4.2. Instances with Product Analytics Dashboard configured and enabled could be vulnerable to SSRF attacks.
Title Server-Side Request Forgery (SSRF) in GitLab
First Time appeared Gitlab
Gitlab gitlab
Weaknesses CWE-918
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published: 2024-10-10T10:02:10.914Z

Updated: 2024-10-10T13:53:37.484Z

Reserved: 2024-09-18T15:30:46.280Z

Link: CVE-2024-8977

cve-icon Vulnrichment

Updated: 2024-10-10T13:53:31.090Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-10T10:15:08.367

Modified: 2024-10-16T17:10:13.220

Link: CVE-2024-8977

cve-icon Redhat

No data.