Debian bug report #703294, favicon.ico passthrough security threat
Short summary: Code in caldav.php to work around errors in rewrite rules potentially introduces security holes. Author suggests to remove code.
The 17.0 major release is coming on May 16, 2024! This version brings many exciting improvements to GitLab, but also removes some deprecated features. We are introducing three breaking change windows during which we expect breaking changes to be deployed to GitLab.com. You can read more about it on our blogpost. The third breaking change window begins 2024-05-06 09:00 UTC and ends 2024-05-08 22:00 UTC.
Short summary: Code in caldav.php to work around errors in rewrite rules potentially introduces security holes. Author suggests to remove code.