A flawed DNS rebinding protection issue was discovered in GitLab CE/EE 10.2 and later in the `url_blocker.rb` which could result in SSRF where the library is utilized.
- https://gitlab.com/gitlab-org/gitlab-ce/issues/63959
- https://hackerone.com/reports/632101
- https://github.com/20142995/nuclei-templates
- https://github.com/ARPSyndicate/cvemon
- https://github.com/Ch0pin/vulnerability-review
- https://github.com/cyb3r-w0lf/nuclei-template-collection