Impact
An authenticated user with reporter permissions who has authored a merge request can reset merge request approval rules due to an authorization check that occurs after the asset is accessed. This flaw allows the user to bypass required approvals, potentially inserting unreviewed code into the repository. The vulnerability is captured by CWE-1280.
Affected Systems
The issue impacts GitLab Enterprise Edition from version 13.1 up to just before 19.1.7, versions 19.2 before 19.2.5, and 19.3 before 19.3.1. All earlier releases remain vulnerable until patched to 19.1.7 or later 19.2.5/19.3.1, according to the vendor’s advisories.
Risk and Exploitability
The CVSS score of 3.5 indicates a moderate impact, and no EPSS data is available, so the likelihood of exploitation is uncertain but not improbable. The flaw is not listed in CISA’s KEV catalog. Attackers need an authenticated reporter role and must have created a merge request; no privilege escalation or remote code execution is required. Replication requires only a standard web interface interaction.
OpenCVE Enrichment