CyberRota Analysis
AI-GeneratedGitLab versions from 13.1 to 19.1.7, 19.2 to 19.2.5, and 19.3 to 19.3.1 are vulnerable to an issue where authenticated users with reporter-role permissions can reset merge request approval rules due to inadequate authorization checks. This could potentially allow unauthorized changes to merge request approvals, impacting the integrity of the code review process. Organizations using affected GitLab versions, especially those with collaborative development environments, should prioritize applying the necessary updates to mitigate this risk.
Original NVD Description
GitLab has remediated an issue in GitLab EE affecting all versions from 13.1 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with reporter-role permissions who authored a merge request could have reset merge request approval rules due to improper authorization checks.
Related CVEs
Other vulnerabilities affecting the same vendor(s)