S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2021-22214 Scanner

Detects 'Server-Side Request Forgery (SSRF)' vulnerability in GitLab affects v. from 10.5 to 13.10.5,from 13.11 to 13.11.5, from 13.12 to 13.12.2.

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.3k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-22214
8.6
CVSSmedium
Exploitable remotely over the internet · no authentication required.

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is limited

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
GitLabby GitLab
>=10.5, <13.10.5
Updated Aug 21, 2026View on NVD →
Detail

GitLab is a web-based Git repository manager that is used for version control, source code management, and continuous integration and delivery. It enables developers to collaborate on code, track bugs, and monitor performance, all from a single platform.

A critical vulnerability, CVE-2021-22214, has been detected in GitLab CE/EE that affects all versions starting from 10.5. This vulnerability enables an unauthenticated attacker, even on a GitLab instance where registration is limited, to exploit a server-side request forgery vulnerability when webhooks are enabled within the internal network.

When this vulnerability is exploited, it can lead to malicious actors gaining unauthorized access to sensitive data stored on the GitLab instance. This includes confidential source code, customer information, and other sensitive business data that could be used for cyber espionage, corporate espionage, or ransomware attacks.

Thanks to the pro features of the s4e.io platform, those who are concerned about the security of their digital assets can easily and quickly learn about vulnerabilities and receive real-time alerts to mitigate risks in a timely manner. By staying informed and taking proactive measures, businesses can better protect their digital assets and reduce the risk of cyber attacks.

 

REFERENCES

Solution Advice

To protect against this vulnerability, it is recommended to take the following precautions:

  • Disable webhooks on the internal network if they are not needed
  • Implement network segmentation to isolate sensitive data from the internal network
  • Regularly update the GitLab instance to ensure that the latest security patches are applied
  • Monitor network traffic for suspicious activity
  • Conduct regular penetration testing and vulnerability assessments to identify and fix any security gaps.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.