CVE-2021-22214
08.06.2021, 15:15
When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is limited
Vendor | Product | Version |
---|---|---|
gitlab | gitlab | 10.5 ≤ 𝑥 < 13.10.5 |
gitlab | gitlab | 13.11 ≤ 𝑥 < 13.11.5 |
gitlab | gitlab | 13.12 ≤ 𝑥 < 13.12.2 |
𝑥
= Vulnerable software versions
References