A single HTTP POST to the commits API bypasses all security controls and reads arbitrary files from a GitLab server. CISA ...