A reflected cross-site script vulnerability in GitLab before versions 13.11.6, 13.12.6 and 14.0.2 allowed an attacker to send a malicious link to a victim and trigger actions on their behalf if they clicked it
| Software | From | Fixed in |
|---|---|---|
| gitlab / gitlab | 14.0.0 | 14.0.2 |
| gitlab / gitlab | 13.12.0 | 13.12.6 |
| gitlab / gitlab | - | 13.11.6 |