Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.2 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to achieve stored cross-site scripting by exploiting GitLab Flavored Markdown.
Problem types
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
18.2.2 (semver) before 18.5.5
18.6 (semver) before 18.6.3
18.7 (semver) before 18.7.1
Credits
Thanks [yvvdwf](https://hackerone.com/yvvdwf) for reporting this vulnerability through our HackerOne bug bounty program
References
gitlab.com/gitlab-org/gitlab/-/issues/562561 (GitLab Issue #562561)
hackerone.com/reports/3297483 (HackerOne Bug Bounty Report #3297483)
about.gitlab.com/...07/patch-release-gitlab-18-7-1-released/