Rating:

SSRF through project mirroring into redis injection RCE.

Original writeup (https://desc0n0cid0.blogspot.com/2019/01/chaining-2-low-impact-bugs-into-gitlab.html).