Loading HuntDB...

GHSA-859x-xr5x-c9x2

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

A server-side request forgery issue has been discovered in GitLab EE affecting all versions starting from 16.8 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. It was possible for an attacker to make requests to internal resources using a custom Maven Dependency Proxy URL

Related CVEs

Key Information

GHSA ID
GHSA-859x-xr5x-c9x2
Published
September 12, 2024 6:31 PM
Last Modified
September 12, 2024 6:31 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: June 15, 2025 6:24 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.