CVE-2019-5474: GitLab

Medium severity, CVSS 6.5. EPSS: 1.1% chance of exploitation in the next 30 days.

An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridden without appropriate permissions.

Affected products

  • GitLab GitLab: from 11.8.0, before 11.11.6 (fixed in 11.11.6); from 12.0.0, before 12.0.4 (fixed in 12.0.4); from 12.1.0, before 12.1.2 (fixed in 12.1.2)

Published 2020-01-28. Last modified 2026-06-17.