CVE-2024-8977: Server-Side Request Forgery (SSRF) in GitLab
An issue has been discovered in GitLab EE affecting all versions starting from 15.10 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior to 17.4.2. Instances with Product Analytics Dashboard configured and enabled could be vulnerable to SSRF attacks.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-8977?
CVE-2024-8977 has a medium severity level due to its potential for SSRF attacks affecting vulnerability exploitation.
How do I fix CVE-2024-8977?
To fix CVE-2024-8977, upgrade your GitLab EE instance to version 17.2.9 or later, or 17.3.5 or later, or 17.4.2 or later depending on your version.
Who is affected by CVE-2024-8977?
CVE-2024-8977 affects all versions of GitLab EE starting from 15.10 up to versions prior to 17.2.9, 17.3.5, and 17.4.2 if Product Analytics Dashboard is configured.
What type of attack is CVE-2024-8977 associated with?
CVE-2024-8977 is associated with Server-Side Request Forgery (SSRF) attacks which can lead to unauthorized access or data exposure.
Is there a workaround for CVE-2024-8977?
Currently, the recommended action for CVE-2024-8977 is to apply the necessary updates as no specific workarounds are documented.