Description
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.10 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows a project maintainer can delete the merge request approval policy via graphQL.
No analysis available yet.
Remediation
Vendor Solution
Upgrade to versions 17.1.1, 17.0.3, 16.11.5 or above.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-46652 | An issue was discovered in GitLab CE/EE affecting all versions starting from 16.10 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows a project maintainer can delete the merge request approval policy via graphQL. |
References
History
Thu, 29 Aug 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* |
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2024-08-29T15:04:59.442Z
Reserved: 2024-05-28T12:30:37.025Z
Link: CVE-2024-5430
Updated: 2024-08-01T21:11:12.743Z
Status : Modified
Published: 2024-06-27T00:15:12.650
Modified: 2024-11-21T09:47:40.157
Link: CVE-2024-5430
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD