CVE-2021-39867

Name
CVE-2021-39867
Description
In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
CONFIRM https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39867.json
MISC https://gitlab.com/gitlab-org/gitlab/-/issues/214401

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:gitlab:gitlab:4.3.0:*:*:*:community:*:*:* gitlab == None == 4.3.0
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* gitlab >= 8.15.0 < 14.1.7
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* gitlab >= 14.2.0 < 14.2.5

Vulnerable and fixed packages

Source package Branch Version Maintainer Status