EXPOSURES › CVE-2021-39935
CVE-2021-39935
HIGH ⌖ ON CISA KEV · EXPLOITEDGitLab SSRF allowed unauthorized external users to manipulate CI Lint API requests
GitLab's Community and Enterprise Editions suffered a Server-Side Request Forgery (SSRF) vulnerability, enabling attackers to manipulate CI Lint API requests, potentially leading to unauthorized actions. This could impact DIB organizations by compromising CI pipelines and sensitive operations.
Shame score — Unpatched SSRF vulnerability actively exploited in the wild, posing a severe risk to CI pipelines and DevOps processes.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
GitLab Community and Enterprise Editions contain a server-side request forgery vulnerability which could allow unauthorized external users to perform Server Side Requests via the CI Lint API.