An authorization bypass vulnerability was discovered in GitLab affecting versions 15.1 prior to 16.7.6, 16.8 prior to 16.8.3, and 16.9 prior to 16.9.1. A developer could bypass CODEOWNERS approvals by creating a merge conflict.
2024-02-22T00:15:51.723
2024-11-21T08:46:31.520
Modified
CVSSv3.1: 7.7 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gitlab | gitlab | < 16.7.6 | Yes |
Application | gitlab | gitlab | < 16.8.3 | Yes |
Application | gitlab | gitlab | 16.9.0 | Yes |