CVE-2024-9870

An external service interaction vulnerability in GitLab EE affecting all versions from 15.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to send requests from the GitLab server to unintended services.
References
Link Resource
https://gitlab.com/gitlab-org/gitlab/-/issues/498911 Exploit Issue Tracking
https://hackerone.com/reports/2734142 Permissions Required
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

History

06 Aug 2025, 18:48

Type Values Removed Values Added
CWE CWE-918
First Time Gitlab gitlab
Gitlab
Summary
  • (es) Una vulnerabilidad de interacción de servicio externo en GitLab EE que afecta a todas las versiones desde 15.11 anterior a 17.6.5, 17.7 anterior a 17.7.4 y 17.8 anterior a 17.8.2 permite a un atacante enviar solicitudes desde el servidor de GitLab a servicios no deseados.
References () https://gitlab.com/gitlab-org/gitlab/-/issues/498911 - () https://gitlab.com/gitlab-org/gitlab/-/issues/498911 - Exploit, Issue Tracking
References () https://hackerone.com/reports/2734142 - () https://hackerone.com/reports/2734142 - Permissions Required
CPE cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

12 Feb 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-12 16:15

Updated : 2025-08-06 18:48


NVD link : CVE-2024-9870

Mitre link : CVE-2024-9870

CVE.ORG link : CVE-2024-9870


JSON object : View

Products Affected

gitlab

  • gitlab
CWE
CWE-441

Unintended Proxy or Intermediary ('Confused Deputy')

CWE-918

Server-Side Request Forgery (SSRF)