← back
CVE-2024-9870mediumCWE-441

Unintended Proxy or Intermediary ('Confused Deputy') in GitLab

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 4.3epss 0.4%
exploitation probability
0.4%top 69% of all CVEs
observed exploitation
nono source reports it
An external service interaction vulnerability in GitLab EE affecting all versions from 15.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to send requests from the GitLab server to unintended services.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected products
GitLab · GitLab