GitLab disclosed on HackerOne: Stored XSS in markdown via the...

### Summary When rendering markdown, links to designs are parsed using the following `link_reference_pattern`: https://gitlab.com/gitlab-org/gitlab/-/blob/v13.12.1-ee/app/models/design_management/design.rb#L168 ```ruby def self.link_reference_pattern @link_reference_pattern ||= begin …