CVE-2021-22175
11.06.2021, 16:15
When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is disabled
Vendor | Product | Version |
---|---|---|
gitlab | gitlab | 10.5.0 ≤ 𝑥 < 13.6.7 |
gitlab | gitlab | 10.5.0 ≤ 𝑥 < 13.6.7 |
gitlab | gitlab | 13.7.0 ≤ 𝑥 < 13.7.7 |
gitlab | gitlab | 13.7.0 ≤ 𝑥 < 13.7.7 |
gitlab | gitlab | 13.8.0 ≤ 𝑥 < 13.8.4 |
gitlab | gitlab | 13.8.0 ≤ 𝑥 < 13.8.4 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References