Description

Gitlab CI Lint API allows validating CI/CD YAML configuration from remote servers. It doesn't require authentication. An attacker may use this feature to perform SSRF (Server-side request forgery) attacks on the server.

Remediation

Upgrade to the latest version of Gitlab

References

Related Vulnerabilities