GitLab 10.5 and later contain a server-side request forgery caused by insecure handling of webhook requests, letting unauthenticated attackers exploit the server for arbitrary requests, exploit requires sending crafted webhook requests.
id: CVE-2021-22175
info:
name: GitLab CI Lint API - Server-Side Request Forgery
author: 0x_Akok
...