Improper validation of ipynb files in GitLab CE/EE version 13.5 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf.
| Software | From | Fixed in |
|---|---|---|
| gitlab / gitlab | 14.4.0 | 14.4.1 |
| gitlab / gitlab | 14.3.0 | 14.3.4 |
| gitlab / gitlab | 13.5.0 | 14.2.6 |