CVE-2011-4319: Translate helper method which may allow an attacker to insert arbitrary code into a page
(updated )
The helper method for i18n translations has a convention whereby translations strings with a name ending in ‘html’ are considered HTML safe. There is also a mechanism for interpolation. It has been discovered that these ‘html’ strings allow arbitrary values to be contained in the interpolated input, and these values are not escaped.
References
Detect and mitigate CVE-2011-4319 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →