CVE-2022-0136Server-Side Request Forgery in Gitlab

Severity
8.1HIGHNVD
EPSS
0.2%
top 58.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 28
Latest updateJan 10

Description

A vulnerability was discovered in GitLab versions 10.5 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1. GitLab was vulnerable to a blind SSRF attack through the Project Import feature.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 2.8 | Impact: 5.2

Affected Packages5 packages

debiandebian/gitlab< gitlab 15.10.8+ds1-2 (sid)
NVDgitlab/gitlab10.5.014.5.4+2
CVEListV5gitlab/gitlab>=10.5, <14.5.4, >=14.6, <14.6.4, >=14.7, <14.7.1+2
gitlabgitlab/gitlab

🔴Vulnerability Details

2
GHSA
GHSA-6c5h-gg2j-qp46: A vulnerability was discovered in GitLab versions 102022-03-29
OSV
CVE-2022-0136: A vulnerability was discovered in GitLab versions 102022-03-28

📋Vendor Advisories

3
Chrome
Stable Channel Update for Desktop: CVE-2023-01342023-01-10
GitLab
CVE-2022-0136: A vulnerability was discovered in GitLab versions 10.5 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1. GitLab was vulnerable to a blind SSRF attack thr2022-03-28
Debian
CVE-2022-0136: gitlab - A vulnerability was discovered in GitLab versions 10.5 to 14.5.4, 14.6 to 14.6.4...2022