CVE-2021-22214: Gitlab CE/EE 10.5 – Server-Side Request Forgery

CVE-2021-22214: Gitlab CE/EE 10.5 - Server-Side Request Forgery-渗透云记 - 专注于网络安全与技术分享
CVE-2021-22214: Gitlab CE/EE 10.5 – Server-Side Request Forgery
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2021-22214: GitLab CE/EE 10.5 – Server-Side Request Forgery

漏洞描述

GitLab CE/EE versions starting from 10.5 are susceptible to a server-side request forgery vulnerability when requests to the internal network for webhooks are enabled, even on a GitLab instance where registration is limited. The same vulnerability actually spans multiple CVEs, due to similar reports that were fixed across separate patches. These CVEs are:

CVE-2021-39935

– CVE-2021-22214

– CVE-2021-22175

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享