CVE-2024-8977

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Oct 10, 2024
Updated: Oct 16, 2024
CWE ID 918

Summary

CVE-2024-8977 is a vulnerability impacting GitLab Enterprise Edition (EE). Affected versions include those before 17.2.9 for 15.10 and earlier, before 17.3.5 for versions 17.3 and later, and before 17.4.2 for versions 17.4 and later. Instances with the Product Analytics Dashboard enabled are at risk for Server Side Request Forgery (SSRF) attacks, allowing attackers to potentially access internal resources or data from the affected GitLab EE instance.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share