CVE-2019-11546: GitLab
Medium severity, CVSS 5.3. EPSS: 0.6% chance of exploitation in the next 30 days.
An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It has a Race Condition which could allow users to approve a merge request multiple times and potentially reach the approval count required to merge.
Affected products
- GitLab GitLab: from 8.6.0, before 11.8.9 (fixed in 11.8.9); from 11.9.0, before 11.9.10 (fixed in 11.9.10); from 11.10.0, before 11.10.2 (fixed in 11.10.2)
Published 2019-09-09. Last modified 2026-06-17.