GMS-2022-6860: Stored XSS in Compare Mode
A malicious content author could add a Javascript payload to a page’s meta description and get it executed in the versioned history compare view.
This vulnerability requires access to the CMS to be deployed. The attacker must then convince a privileged user to access the version history for that page.
References
Detect and mitigate GMS-2022-6860 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →