An issue was discovered in GitLab Community Edition and Enterprise Edition before 10.7.6, 10.8.x before 10.8.5, and 11.x before 11.0.1. The wiki contains a persistent XSS issue due to a lack of output encoding affecting a specific markdown feature.
2018-08-03T18:29:00.313
2024-11-21T03:45:31.730
Modified
CVSSv3.0: 5.4 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gitlab | gitlab | < 10.7.6 | Yes |
Application | gitlab | gitlab | < 10.7.6 | Yes |
Application | gitlab | gitlab | < 10.8.5 | Yes |
Application | gitlab | gitlab | < 10.8.5 | Yes |
Application | gitlab | gitlab | < 11.0.1 | Yes |
Application | gitlab | gitlab | < 11.0.1 | Yes |