gitlab-ce is vulnerable to Cross-Site Scripting (XSS)
82
High Risk
The Markdown JSON table renderer does not adequately sanitize user-controlled data. An authenticated attacker can craft content that induces a targeted user to perform unintended state-changing HTTP requests in their session. The fix sanitizes JSON table renderer input so crafted Markdown cannot drive those requests.
You are affected if you are using a version that falls within the vulnerable range.
gitlab-ce is vulnerable to Cross-Site Scripting (XSS) in versions 15.3.0 - 19.1.7, 19.2.0 - 19.2.5 and 19.3.0 - 19.3.1.
Upgrade the gitlab-ce library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.