A vulnerability was discovered in GitLab versions prior to 13.1. Username format restrictions could be bypassed allowing for html tags to be added.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "12.10.13"
},
{
"introduced": "13.0.0"
},
{
"fixed": "13.0.8"
},
{
"introduced": "13.1.0"
},
{
"fixed": "13.1.2"
}
]
}