CVE-2024-8635Server-Side Request Forgery in Gitlab

Severity
6.5MEDIUMNVD
EPSS
0.1%
top 78.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 12

Description

A server-side request forgery issue has been discovered in GitLab EE affecting all versions starting from 16.8 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. It was possible for an attacker to make requests to internal resources using a custom Maven Dependency Proxy URL

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages5 packages

CVEListV5gitlab/gitlab16.817.1.7+2
NVDgitlab/gitlab16.8.017.1.7+2
debiandebian/gitlab
gitlabgitlab/gitlab

🔴Vulnerability Details

1
GHSA
GHSA-859x-xr5x-c9x2: A server-side request forgery issue has been discovered in GitLab EE affecting all versions starting from 162024-09-12

📋Vendor Advisories

2
GitLab
CVE-2024-8635: A server-side request forgery issue has been discovered in GitLab EE affecting all versions starting from 16.8 prior to 17.1.7, from 17.2 prior to 17.2024-09-12
Debian
CVE-2024-8635: gitlab - A server-side request forgery issue has been discovered in GitLab EE affecting a...2024

🕵️Threat Intelligence

1
Bleepingcomputer
GitLab warns of critical pipeline execution vulnerability2024-09-12