S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 23, 2025

CVE-2021-22175 Scanner

CVE-2021-22175 Scanner - Server-Side-Request-Forgery vulnerability in GitLab

Est. Time~1 minutes
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.1k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2021-22175
9.8
CVSSmedium
Exploitable remotely over the internet · no authentication required.

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is disabled

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
GitLabby GitLab
>=10.5, <13.6.7
Updated Aug 21, 2026View on NVD →
Detail

GitLab is a web-based DevOps lifecycle tool that provides a Git repository manager, CI/CD pipelines, and many other features for developers and organizations worldwide. It is utilized by various teams for version control, collaboration, and deployment in software development projects. With its comprehensive suite of tools, GitLab streamlines code management and continuous integration/continuous deployment (CI/CD) processes. Organizations across multiple industries use GitLab to improve their development workflow, enhance productivity, and automate the deployment pipeline. The platform supports a wide range of integrations with other popular development tools, allowing for cohesive and efficient project management. GitLab's extensive feature set and open-source foundation make it a popular choice among developers looking to streamline their workflow.

Server-Side Request Forgery (SSRF) is a vulnerability that allows an attacker to manipulate server interactions through faulty input validation. In this case, GitLab's handling of webhook requests is exploited to execute unauthorized requests within the internal infrastructure. This vulnerability arises from improperly handled remote file inclusions, specifically when unauthenticated users send crafted webhook requests. The unauthorized requests could bypass firewall rules and access restricted network resources or sensitive endpoints. As a high-severity vulnerability, SSRF poses significant security risks, potentially compromising internal systems and disclosing confidential information. It emphasizes the need for secure coding practices and robust input validation mechanisms.

The SSRF vulnerability in GitLab can be exploited by sending crafted webhook requests to the CI Lint API endpoint. Exploiting this vulnerability allows attackers to make arbitrary requests through the GitLab server as a proxy. The vulnerability stems from improper validation of user-controlled input that defines remote URLs. As a result, an attacker can control where requests are sent, enabling them to access internal services and networks. The HTTP request payload manipulates the "content" parameter in the API call, instructing the server to include content from an attacker-controlled URL. This attack vector can expose sensitive services or data that are otherwise shielded from unauthorized access.

If exploited, this SSRF vulnerability can lead to unauthorized access to internal systems, potential leakage of private data, and disruption of service operations. Attackers may leverage the vulnerability to access sensitive information or gain a foothold within the organization's internal network. Information disclosure could lead to further attacks, such as pivoting to other internal resources or escalating privileges within the network. Compromised internal services could result in significant operational disruptions or unauthorized code execution. Security measures, such as network segmentation and intrusion detection, are crucial in mitigating the impact of this vulnerability.

REFERENCES

Solution Advice
  • Update GitLab to the latest version where the vulnerability is patched.
  • Ensure proper validation and sanitization of user inputs across all GitLab API endpoints.
  • Implement network segmentation and firewall rules to restrict unnecessary internal request access.
  • Conduct regular security audits and penetration tests to identify potential vulnerabilities.
  • Deploy security monitoring and intrusion detection systems to detect and respond to unauthorized access attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.