Related Vulnerabilities: CVE-2018-12607  

The charts feature contained a persistent XSS issue due to a lack of output encoding.

Severity Medium

Remote Yes

Type Cross-site scripting

Description

The charts feature contained a persistent XSS issue due to a lack of output encoding.

AVG-726 gitlab 11.0.0-1 11.0.1-1 Medium Fixed

04 Jul 2018 ASA-201807-1 AVG-726 gitlab Medium multiple issues