CVE-2024-8635: Server-Side Request Forgery (SSRF) in GitLab
A server-side request forgery issue has been discovered in GitLab EE affecting all versions starting from 16.8 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. It was possible for an attacker to make requests to internal resources using a custom Maven Dependency Proxy URL
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-8635?
CVE-2024-8635 has a high severity rating due to its potential for exploitation through server-side request forgery.
How do I fix CVE-2024-8635?
To fix CVE-2024-8635, upgrade GitLab to version 17.1.7 or later, or 17.2.5 or later, or 17.3.2 or later.
Which versions of GitLab are affected by CVE-2024-8635?
CVE-2024-8635 affects all versions of GitLab starting from 16.8 up to 17.1.6, from 17.2.0 up to 17.2.4, and from 17.3.0 up to 17.3.1.
What type of vulnerability is CVE-2024-8635?
CVE-2024-8635 is a server-side request forgery (SSRF) vulnerability.
Can I mitigate CVE-2024-8635 without upgrading?
Mitigation strategies for CVE-2024-8635 are limited, and upgrading is the recommended approach to eliminate the vulnerability.