Insufficient input sanitization in Mermaid markdown in GitLab CE/EE version 11.4 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown
| Software | From | Fixed in |
|---|---|---|
| gitlab / gitlab | 14.1.0 | 14.1.2 |
| gitlab / gitlab | 14.0.0 | 14.0.7 |
| gitlab / gitlab | 11.4.0 | 13.12.9 |