A blind SSRF in GitLab CE/EE affecting all from 11.3 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 allows an attacker to connect to local addresses when configuring a malicious GitLab Runner.
2023-01-27T22:15:08.913
2025-03-27T21:15:40.680
Modified
CVSSv3.1: 3.5 (LOW)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gitlab | gitlab | < 15.4.6 | Yes |
Application | gitlab | gitlab | < 15.4.6 | Yes |
Application | gitlab | gitlab | < 15.5.5 | Yes |
Application | gitlab | gitlab | < 15.5.5 | Yes |
Application | gitlab | gitlab | 15.6.0 | Yes |
Application | gitlab | gitlab | 15.6.0 | Yes |