An issue was discovered in GitLab Community Edition and Enterprise Edition before 10.7.6, 10.8.x before 10.8.5, and 11.x before 11.0.1. The wiki contains a persistent XSS issue due to a lack of output encoding affecting a specific markdown feature.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "10.7.6"
},
{
"introduced": "0"
},
{
"fixed": "10.7.6"
},
{
"introduced": "10.8.0"
},
{
"fixed": "10.8.5"
},
{
"introduced": "10.8.0"
},
{
"fixed": "10.8.5"
},
{
"introduced": "11.0.0"
},
{
"fixed": "11.0.1"
},
{
"introduced": "11.0.0"
},
{
"fixed": "11.0.1"
}
]
}