CVE-2018-12605: GitLab

Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.

An issue was discovered in GitLab Community Edition and Enterprise Edition 10.7.x before 10.7.6. The usage of 'url_for' contained a XSS issue due to it allowing arbitrary protocols as a parameter.

Affected products

  • GitLab GitLab: from 10.7.0, before 10.7.6 (fixed in 10.7.6)

Published 2018-08-03. Last modified 2026-06-17.