CVE-2019-15723

An issue was discovered in GitLab Community and Enterprise Edition 11.9.x and 11.10.x before 11.10.1. Merge requests created by email could be used to bypass push rules in certain situations.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

History

21 Nov 2024, 04:29

Type Values Removed Values Added
References () https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/ - Release Notes, Vendor Advisory () https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/ - Release Notes, Vendor Advisory
References () https://gitlab.com/gitlab-org/gitlab-ee/issues/11302 - Broken Link () https://gitlab.com/gitlab-org/gitlab-ee/issues/11302 - Broken Link

Information

Published : 2019-09-16 17:15

Updated : 2024-11-21 04:29


NVD link : CVE-2019-15723

Mitre link : CVE-2019-15723

CVE.ORG link : CVE-2019-15723


JSON object : View

Products Affected

gitlab

  • gitlab
CWE
CWE-862

Missing Authorization