Source code disclosure merge request diff
Todos improper access control
URL rel attribute not set
Persistent XSS Autocompletion
SSRF repository mirroring
CI job token LFS error message disclosure
Secret CI variable exposure
Guest user CI job disclosure
Persistent XSS label reference
Persistent XSS wiki in IE browser
SSRF in project imports with LFS
Improper access control CI/CD settings
Missing authorization control merge requests
Improper access control branches and tags
Missing authentication for Prometheus alert endpoint