MEDIUM
CVE-2019-15723
CVSS
5.3
Description
An issue was discovered in GitLab Community and Enterprise Edition 11.9.x and 11.10.x before 11.10.1. Merge requests created by email could be used to bypass push rules in certain situations.
Summary dbcve.org
In GitLab 11.9.x and 11.10.x, merge requests created via email could bypass push rule enforcement. Push rules (which can block commits matching certain patterns, require signed commits, etc.) were not properly applied when merge requests were created through the email submission channel, allowing attackers to circumvent security controls.
Mitigation
Upgrade GitLab to version 11.10.1 or later where the push rules are properly enforced for email-created merge requests.
Weakness (CWE)
CWE-862
Missing Authorization
EPSS Score
1.27%
Probability of exploitation in next 30 days
68.5th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.