CVE-2024-9870: Unintended Proxy or Intermediary ('Confused Deputy') in GitLab
An external service interaction vulnerability in GitLab EE affecting all versions from 15.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to send requests from the GitLab server to unintended services.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-9870?
CVE-2024-9870 is classified as a vulnerability that poses a risk of external service interaction.
How do I fix CVE-2024-9870?
To mitigate CVE-2024-9870, upgrade GitLab EE to versions 17.6.5, 17.7.4, or 17.8.2 or later.
What versions are affected by CVE-2024-9870?
CVE-2024-9870 affects all GitLab EE versions from 15.11 up to but not including 17.6.5, 17.7 up to but not including 17.7.4, and 17.8 up to but not including 17.8.2.
What type of vulnerability is CVE-2024-9870?
CVE-2024-9870 is an external service interaction vulnerability.
Who is impacted by CVE-2024-9870?
All users of GitLab EE versions from 15.11 to versions prior to 17.6.5, 17.7.4, and 17.8.2 are impacted by CVE-2024-9870.