An issue has been discovered in GitLab EE/CE affecting all versions starting from 8.0 before 16.4. The product did not sufficiently warn about security implications of granting merge rights to protected branches.
2024-10-01T10:15:02.997
2024-12-12T20:00:32.067
Analyzed
CVSSv3.1: 6.6 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gitlab | gitlab | < 16.4.0 | Yes |
Application | gitlab | gitlab | < 16.4.0 | Yes |