A crafted tag in the Jupyter Notebook viewer in GitLab EE/CE affecting all versions before 15.1.6, 15.2 to 15.2.4, and 15.3 to 15.3.2 allows an attacker to issue arbitrary HTTP requests
| Software | From | Fixed in |
|---|---|---|
| gitlab / gitlab | 15.3 | 15.3.2 |
| gitlab / gitlab | 15.2 | 15.2.4 |
| gitlab / gitlab | - | 15.1.6 |