CVE-2022-1188: SSRF
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 where a blind SSRF attack through the repository mirroring feature was possible.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-1188?
CVE-2022-1188 has been classified as a medium severity vulnerability due to its potential for exploiting blind SSRF attacks.
How do I fix CVE-2022-1188?
To fix CVE-2022-1188, upgrade your GitLab instance to versions 14.7.7, 14.8.5, or 14.9.2 or later.
Which versions of GitLab are affected by CVE-2022-1188?
CVE-2022-1188 affects GitLab versions from 12.1.0 to below 14.7.7, 14.8.0 to below 14.8.5, and 14.9.0 to below 14.9.2.
What type of attack does CVE-2022-1188 allow?
CVE-2022-1188 allows a blind Server-Side Request Forgery (SSRF) attack through the repository mirroring feature.
Who discovered CVE-2022-1188?
CVE-2022-1188 was reported through GitLab's issue tracking and security reporting frameworks.