CVE-2019-15724 (NVD)

2019-09-16

An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.2.1. Label descriptions are vulnerable to HTML injection.

Products Gitlab
Type Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') (CWE-74)
First patch - None (likely due to unavailable code)
Links https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/
https://gitlab.com/gitlab-org/gitlab-ce/issues/60888