CISA warns of five-year-old GitLab flaw exploited in attacks
ID: 12bb26dd-8e66-5e38-a4b7-5f1db2f8dd72
STIX ID: report--12bb26dd-8e66-5e38-a4b7-5f1db2f8dd72
Feed Name: Bleeping Computer
Threat Score
CISA added CVE-2021-39935, a five-year-old GitLab SSRF flaw patched in December 2021, to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch systems within three weeks due to active exploitation; the report emphasizes widespread exposure (Shodan >49,000 GitLab instances, GitLab used by millions and many Fortune 100 companies) and urges organizations to apply vendor mitigations or discontinue affected products.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
