ZeroHour

CVE-2024-9870

PoC
CVSS 3.1
8.8 high
EPSS
<1%p33
Published
()
Modified
Description

An external service interaction vulnerability in GitLab EE affecting all versions from 15.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to send requests from the GitLab server to unintended services.

Vendors
gitlab
Products
gitlab
Weakness
CWE-441, CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.