GitLab
Discovery
Version Enumeration
# In page source or footer
curl -s http://TARGET | grep 'gitlab'
# Via API (if accessible)
curl -s http://TARGET/api/v4/versionUsername Enumeration
config.lock_strategy = :failed_attempts
config.maximum_attempts = 10Registration Page Enumeration
Public Repositories
Authenticated RCE (CVE-2021-22205)
Import Feature RCE
API Token Theft
Default Paths
Path
Description
Authenticated RCE (CVE-2021-22205)
Username Enumeration
CVEs
CVE
Description
Last updated