HIGH
CVE-2019-12441
CVSS
7.5
Description
An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. The protected branches feature contained a access control issue which resulted in a bypass of the protected branches restriction rules. It has Incorrect Access Control.
Summary dbcve.org
GitLab Community and Enterprise Edition 8.4 through 11.11 contains an Incorrect Access Control vulnerability in the protected branches feature, allowing authenticated users to bypass restriction rules meant to protect branches from unauthorized modifications such as force pushes, deletion, or merges.
Mitigation
Upgrade GitLab to a version beyond 11.11 where the access control logic for protected branches has been corrected.
Weakness (CWE)
CWE-732
Incorrect Permission Assignment
EPSS Score
0.94%
Probability of exploitation in next 30 days
59.3th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.