mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-26 05:17:47 +02:00
850 B
850 B
CVE-2021-22175
Description
When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is disabled
POC
Reference
- https://gitlab.com/gitlab-org/gitlab/-/issues/294178
- https://gitlab.com/gitlab-org/gitlab/-/issues/294178