Client-Side code injection through Feature Flag name in GitLab CE/EE starting with 11.9 allows a specially crafted feature flag name to PUT requests on behalf of other users via clicking on a link
{
"versions": [
{
"introduced": "13.9.0"
},
{
"fixed": "13.11.6"
},
{
"introduced": "13.9.0"
},
{
"fixed": "13.11.6"
},
{
"introduced": "13.12.0"
},
{
"fixed": "13.12.6"
},
{
"introduced": "13.12.0"
},
{
"fixed": "13.12.6"
},
{
"introduced": "14.0.0"
},
{
"fixed": "14.0.2"
},
{
"introduced": "14.0.0"
},
{
"fixed": "14.0.2"
}
]
}