An issue has been discovered in GitLab EE affecting all versions starting from 15.10 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior to 17.4.2. Instances with Product Analytics Dashboard configured and enabled could be vulnerable to SSRF attacks.
                
            References
                    | Link | Resource | 
|---|---|
| https://gitlab.com/gitlab-org/gitlab/-/issues/491060 | Broken Link | 
| https://hackerone.com/reports/2697456 | Permissions Required | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    16 Oct 2024, 17:10
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
 | |
| References | () https://gitlab.com/gitlab-org/gitlab/-/issues/491060 - Broken Link | |
| References | () https://hackerone.com/reports/2697456 - Permissions Required | |
| CPE | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | |
| First Time | Gitlab gitlab Gitlab | |
| CVSS | v2 : v3 : | v2 : unknown v3 : 8.1 | 
10 Oct 2024, 10:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2024-10-10 10:15
Updated : 2024-10-16 17:10
NVD link : CVE-2024-8977
Mitre link : CVE-2024-8977
CVE.ORG link : CVE-2024-8977
JSON object : View
Products Affected
                gitlab
- gitlab
CWE
                
                    
                        
                        CWE-918
                        
            Server-Side Request Forgery (SSRF)
