CVE-2021-39935
גבוהה 7.5 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Unauthorized external users could perform Server Side Requests via the CI Lint API
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - EPSS — סבירות ניצול
- 36% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-918
מוצרים מושפעים
gitlab: gitlab
קישורים
- https://gitlab.com/gitlab-org/gitlab/-/issues/346187 Issue TrackingVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/346187 Issue TrackingVendor Advisory
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39935.json Third Party Advisory
- https://hackerone.com/reports/1236965 Permissions RequiredThird Party Advisory
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39935.json Third Party Advisory
- https://hackerone.com/reports/1236965 Permissions RequiredThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource