Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the CI job component resulting in persistent cross site scripting.
| Software | From | Fixed in |
|---|---|---|
| gitlab / gitlab | 10.3.0 | 10.3.3.x |
| gitlab / gitlab | 10.2.0 | 10.2.5.x |
| gitlab / gitlab | 10.1.0 | 10.1.5.x |
| debian / debian_linux | 9.0 | 9.0.x |