id: gitlab-public-snippets info: name: GitLab public snippets author: pdteam severity: info tags: gitlab,exposure,misconfig reference: - https://gist.github.com/vysecurity/20311c29d879e0aba9dcffbe72a88b10 - https://twitter.com/intigriti/status/1375078783338876929 requests: - method: GET path: - "{{BaseURL}}/explore/snippets" - "{{BaseURL}}/-/snippets" matchers-condition: and matchers: - type: word words: - 'Snippets · Explore · GitLab' - type: status status: - 200 - type: word negative: true condition: or words: - "No snippets found" - "Nothing here."