GitLab has released the planned security updates related to CVE-2016-4340 (https://about.gitlab.com/2016/04/28/gitlab-major-security-update-for-cve-2016-4340/). I can't speak for all versions but I was able to update my v8.7.0 installation to v8.7.1 by following the instructions at https://gitlab.com/gitlab-org/gitlab-ce/blob/master/doc/update/patch_versions.md.