CVE-2020-8902: Server-Side Request Forgery (SSRF)
(updated )
An attacker can use a specially crafted webpage to force a rendertron headless chrome process to render internal sites it has access to, and display it as a screenshot.
References
Detect and mitigate CVE-2020-8902 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →