When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is limited
| Software | From | Fixed in |
|---|---|---|
| gitlab / gitlab | 13.12 | 13.12.2 |
| gitlab / gitlab | 13.11 | 13.11.5 |
| gitlab / gitlab | 10.5 | 13.10.5 |