First published: Mon Sep 09 2019(Updated: )
An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It has a Race Condition which could allow users to approve a merge request multiple times and potentially reach the approval count required to merge.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=8.6.0<11.8.9 | |
GitLab | >=8.6.0<11.8.9 | |
GitLab | >=11.9.0<11.9.10 | |
GitLab | >=11.9.0<11.9.10 | |
GitLab | >=11.10.0<11.10.2 | |
GitLab | >=11.10.0<11.10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11546 has a medium severity level due to the potential for unauthorized approvals in merge requests.
To fix CVE-2019-11546, upgrade your GitLab Community or Enterprise Edition to versions 11.8.9, 11.9.10, or 11.10.2 or later.
CVE-2019-11546 allows users to potentially approve a merge request multiple times, which can disrupt the intended approval workflow.
CVE-2019-11546 affects GitLab versions before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2.
CVE-2019-11546 is considered a local vulnerability as it requires authenticated users to exploit the race condition.