MEDIUM

CVE-2019-15723

Gitlab GitLab 2019-09-16 CVSS v3.1
CVSS
5.3

Description

An issue was discovered in GitLab Community and Enterprise Edition 11.9.x and 11.10.x before 11.10.1. Merge requests created by email could be used to bypass push rules in certain situations.

Summary dbcve.org

In GitLab 11.9.x and 11.10.x, merge requests created via email could bypass push rule enforcement. Push rules (which can block commits matching certain patterns, require signed commits, etc.) were not properly applied when merge requests were created through the email submission channel, allowing attackers to circumvent security controls.

Mitigation

Upgrade GitLab to version 11.10.1 or later where the push rules are properly enforced for email-created merge requests.

Weakness (CWE)

CWE-862 Missing Authorization

EPSS Score

1.27%
Probability of exploitation in next 30 days
68.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE