An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. blog-viewer has stored XSS during repository browsing, if package.json exists. .
2023-04-16T00:15:07.103
2025-02-06T17:15:09.467
Modified
CVSSv3.1: 5.4 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gitlab | gitlab | < 11.1.7 | Yes |
Application | gitlab | gitlab | < 11.1.7 | Yes |
Application | gitlab | gitlab | < 11.2.4 | Yes |
Application | gitlab | gitlab | < 11.2.4 | Yes |
Application | gitlab | gitlab | 11.3.0 | Yes |
Application | gitlab | gitlab | 11.3.0 | Yes |