CVE-2024-9870Confused Deputy in Gitlab

Severity
8.8HIGHNVD
EPSS
0.0%
top 92.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 12

Description

An external service interaction vulnerability in GitLab EE affecting all versions from 15.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to send requests from the GitLab server to unintended services.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages5 packages

CVEListV5gitlab/gitlab15.1117.6.5+2
NVDgitlab/gitlab15.11.017.6.5+2
debiandebian/gitlab
gitlabgitlab/gitlab

🔴Vulnerability Details

2
OSV
CVE-2024-9870: An external service interaction vulnerability in GitLab EE affecting all versions from 152025-02-12
GHSA
GHSA-22qj-f25c-22mc: An external service interaction vulnerability in GitLab EE affecting all versions from 152025-02-12

📋Vendor Advisories

2
GitLab
CVE-2024-9870: An external service interaction vulnerability in GitLab EE affecting all versions from 15.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to2025-02-12
Debian
CVE-2024-9870: gitlab - An external service interaction vulnerability in GitLab EE affecting all version...2024