A single HTTP POST request to the /api/v4/projects/{id}/repository/commits/ endpoint is sufficient to bypass security controls and read arbitrary files from a GitLab server. This path traversal ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results