An issue was discovered in GitLab Community and Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows XSS.
{
"versions": [
{
"introduced": "11.2.0"
},
{
"fixed": "11.4.13"
},
{
"introduced": "11.2.0"
},
{
"fixed": "11.4.13"
},
{
"introduced": "11.5.0"
},
{
"fixed": "11.5.6"
},
{
"introduced": "11.5.0"
},
{
"fixed": "11.5.6"
},
{
"introduced": "11.6.0"
},
{
"fixed": "11.6.1"
},
{
"introduced": "11.6.0"
},
{
"fixed": "11.6.1"
}
]
}