A vulnerability was discovered in GitLab starting with version 12. GitLab was vulnerable to a blind SSRF attack since requests to shared address space were not blocked.
2022-03-28T19:15:08.257
2024-11-21T06:38:13.897
Modified
CVSSv3.1: 3.1 (LOW)
AV:N/AC:L/Au:N/C:P/I:P/A:N
10.0
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gitlab | gitlab | ≤ 14.5.4 | Yes |
Application | gitlab | gitlab | ≤ 14.6.4 | Yes |
Application | gitlab | gitlab | ≤ 14.7.1 | Yes |