When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is limited
- https://github.com/ARPSyndicate/cvemon
- https://github.com/ARPSyndicate/kenzer-templates
- https://github.com/SexyBeast233/SecBooks
- https://github.com/Vulnmachines/gitlab-cve-2021-22214
- https://github.com/YuraveON/YuraveON
- https://github.com/antx-code/CVE-2021-22214
- https://github.com/nomi-sec/PoC-in-GitHub
- https://github.com/r0ckysec/CVE-2021-22214
- https://github.com/righel/gitlab-version-nse
- https://github.com/vin01/CVEs