An issue was discovered in GitLab CE/EE affecting all versions starting from 16.10 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows a project maintainer can delete the merge request approval policy via graphQL.
Fixes

Solution

Upgrade to versions 17.1.1, 17.0.3, 16.11.5 or above.


Workaround

No workaround given by the vendor.

History

Thu, 29 Aug 2024 15:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*

cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2024-08-29T15:04:59.442Z

Reserved: 2024-05-28T12:30:37.025Z

Link: CVE-2024-5430

cve-icon Vulnrichment

Updated: 2024-08-01T21:11:12.743Z

cve-icon NVD

Status : Modified

Published: 2024-06-27T00:15:12.650

Modified: 2024-11-21T09:47:40.157

Link: CVE-2024-5430

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.