Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable to an Insecure Temporary File in the project import component resulting remote code execution.
https://www.debian.org/security/2018/dsa-4145
https://hackerone.com/reports/302959
https://gitlab.com/gitlab-org/gitlab-ce/issues/41757
https://gitlab.com/gitlab-com/infrastructure/issues/3510
https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/