CVE-2022-0249Server-Side Request Forgery in Gitlab

Severity
9.1CRITICALNVD
EPSS
0.2%
top 53.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 28
Latest updateMar 29

Description

A vulnerability was discovered in GitLab starting with version 12. GitLab was vulnerable to a blind SSRF attack since requests to shared address space were not blocked.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 3.9 | Impact: 5.2

Affected Packages4 packages

debiandebian/gitlab< gitlab 15.10.8+ds1-2 (sid)
NVDgitlab/gitlab12.014.5.4+2
CVEListV5gitlab/gitlab>=12.0, <14.5.4, >=14.6, <14.6.4, >=14.7, <14.7.1+2
gitlabgitlab/gitlab

🔴Vulnerability Details

2
GHSA
GHSA-q7f8-fr48-qw7g: A vulnerability was discovered in GitLab starting with version 122022-03-29
OSV
CVE-2022-0249: A vulnerability was discovered in GitLab starting with version 122022-03-28

📋Vendor Advisories

2
GitLab
CVE-2022-0249: A vulnerability was discovered in GitLab starting with version 12. GitLab was vulnerable to a blind SSRF attack since requests to shared address space2022-03-28
Debian
CVE-2022-0249: gitlab - A vulnerability was discovered in GitLab starting with version 12. GitLab was vu...2022