In GitLab EE 11.3 through 12.5.3, 12.4.5, and 12.3.8, insufficient parameter sanitization for the Maven package registry could lead to privilege escalation and remote code execution vulnerabilities under certain conditions.
| Software | From | Fixed in |
|---|---|---|
| gitlab / gitlab | 12.4.0 | 12.4.5.x |
| gitlab / gitlab | 12.5.0 | 12.5.3.x |
| gitlab / gitlab | 11.3.0 | 12.3.8.x |