When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is disabled
| Software | From | Fixed in |
|---|---|---|
| gitlab / gitlab | 13.8.0 | 13.8.4 |
| gitlab / gitlab | 13.7.0 | 13.7.7 |
| gitlab / gitlab | 10.5.0 | 13.6.7 |