A blind SSRF vulnerability was identified in all versions of GitLab EE prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 which allows an attacker to connect to a local host.
2023-01-27T18:15:16.183
2025-03-28T15:15:42.973
Modified
CVSSv3.1: 4.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gitlab | gitlab | < 15.4.6 | Yes |
Application | gitlab | gitlab | < 15.5.5 | Yes |
Application | gitlab | gitlab | < 15.6.1 | Yes |