CVE-2021-39935
Severity CVSS v4.0:
Pending analysis
Type:
CWE-918
Server-Side Request Forgery (SSRF)
Publication date:
13/12/2021
Last modified:
15/12/2021
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Unauthorized external users could perform Server Side Requests via the CI Lint API
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | 10.5.0 (including) | 14.3.6 (excluding) |
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | 10.5.0 (including) | 14.3.6 (excluding) |
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | 14.4.0 (including) | 14.4.4 (excluding) |
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | 14.4.0 (including) | 14.4.4 (excluding) |
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | 14.5.0 (including) | 14.5.2 (excluding) |
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | 14.5.0 (including) | 14.5.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page