EXPOSURES › CVE-2021-22175
CVE-2021-22175
HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
⚡ RCE
⌖ EXPLOITED IN THE WILD
SHAME 72/100
exploited-in-wildunpatched
GitLab exposed SSRF, enabling internal network requests exploited in the wild
GitLab's SSRF vulnerability, enabled by default for webhooks, was actively exploited, leading to potential unauthorized access to internal networks.
Shame score — Negligence in enabling a critical vulnerability without proper configuration controls.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PLAYERS IMPLICATED
DESCRIPTION
GitLab contains a server-side request forgery (SSRF) vulnerability when requests to the internal network for webhooks are enabled.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.