Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the labels component resulting in persistent cross site scripting.
| Software | From | Fixed in |
|---|---|---|
| gitlab / gitlab | 10.3.0 | 10.3.3.x |
| gitlab / gitlab | 10.0.0 | 10.1.5.x |
| gitlab / gitlab | 10.2.0 | 10.2.5.x |
| gitlab / gitlab | 9.0.0 | 9.5.10.x |