Cross-site scripting in Gitlab Community Edition - CVE-2019-11547
Published: September 9, 2019 / Updated: July 17, 2020
Gitlab Community Edition
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It has Improper Encoding or Escaping of Output. The branch name on new merge request notification emails isn't escaped, which could potentially lead to XSS issues.