CVE-2024-9870

An external service interaction vulnerability in GitLab EE affecting all versions from 15.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to send requests from the GitLab server to unintended services.
Configurations

No configuration.

History

12 Feb 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-12 16:15

Updated : 2025-02-12 16:15


NVD link : CVE-2024-9870

Mitre link : CVE-2024-9870

CVE.ORG link : CVE-2024-9870


JSON object : View

Products Affected

No product.

CWE
CWE-441

Unintended Proxy or Intermediary ('Confused Deputy')