CVE-2024-8977
CVSS 3.1 Score 8.1 of 10 (high)
Details
Published Oct 10, 2024
Updated: Oct 16, 2024
CWE ID 918
Summary
CVE-2024-8977 is a vulnerability impacting GitLab Enterprise Edition (EE). Affected versions include those before 17.2.9 for 15.10 and earlier, before 17.3.5 for versions 17.3 and later, and before 17.4.2 for versions 17.4 and later. Instances with the Product Analytics Dashboard enabled are at risk for Server Side Request Forgery (SSRF) attacks, allowing attackers to potentially access internal resources or data from the affected GitLab EE instance.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- GitLab
Affected Vendors
- GitLab Inc.