CVE-2021-39894: SSRF
In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vulnerability exists in Fogbugz importer which may be used by attackers to exploit Server Side Request Forgery attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-39894?
CVE-2021-39894 is classified as a high severity vulnerability due to its ability to facilitate Server Side Request Forgery attacks.
How do I fix CVE-2021-39894?
To remediate CVE-2021-39894, upgrade GitLab to versions 14.1.8, 14.2.6, or 14.3.1 or later.
What versions of GitLab are affected by CVE-2021-39894?
CVE-2021-39894 affects all versions of GitLab CE/EE from version 8.0 up to but not including 14.1.8, 14.2.6, and 14.3.1.
Can CVE-2021-39894 be exploited remotely?
Yes, CVE-2021-39894 can be exploited remotely if an attacker sends specially crafted DNS requests.
What type of attacks can CVE-2021-39894 enable?
CVE-2021-39894 can enable Server Side Request Forgery (SSRF) attacks that may lead to information disclosure or unauthorized actions.