Skip to content
Projects
Groups
Snippets
Help
Loading...
Help
Support
Keyboard shortcuts
?
Submit feedback
Contribute to GitLab
Sign in / Register
Toggle navigation
G
gitlab-ce
Project overview
Project overview
Details
Activity
Releases
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Issues
0
Issues
0
List
Boards
Labels
Milestones
Merge Requests
1
Merge Requests
1
Analytics
Analytics
Repository
Value Stream
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Create a new issue
Commits
Issue Boards
Open sidebar
nexedi
gitlab-ce
Commits
f230c665
Commit
f230c665
authored
Jan 04, 2020
by
Ben Bodenmiller
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
Improve formatting of blacklisted IPs
parent
ff30cda5
Changes
1
Hide whitespace changes
Inline
Side-by-side
Showing
1 changed file
with
2 additions
and
2 deletions
+2
-2
doc/security/webhooks.md
doc/security/webhooks.md
+2
-2
No files found.
doc/security/webhooks.md
View file @
f230c665
...
...
@@ -35,8 +35,8 @@ to endpoints like `http://localhost:123/some-resource/delete`.
To prevent this type of exploitation from happening, starting with GitLab 10.6,
all Webhook requests to the current GitLab instance server address and/or in a
private network will be forbidden by default. That means that all requests made
to
127.0.0.1, ::1 and 0.0.0.0, as well as IPv4 10.0.0.0/8, 172.16.0.0/12
,
192.
168.0.0/16 and IPv6 site-local (ffc0::/10
) addresses won't be allowed.
to
`127.0.0.1`
,
`::1`
and
`0.0.0.0`
, as well as IPv4
`10.0.0.0/8`
,
`172.16.0.0/12`
,
`192.168.0.0/16`
and IPv6 site-local (
`ffc0::/10`
) addresses won't be allowed.
This behavior can be overridden by enabling the option
*
"Allow requests to the
local network from web hooks and services"
* in the *
"Outbound requests"
*
section
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment