Insufficient validation of authentication parameters in GitLab Pages for GitLab 11.5+ allows an attacker to steal a victim's API token if they click on a maliciously crafted link
| Software | From | Fixed in |
|---|---|---|
| gitlab / gitlab | 13.7.0 | 13.7.2 |
| gitlab / gitlab | 13.6.0 | 13.6.4 |
| gitlab / gitlab | 11.5.0 | 13.5.6 |