An issue has been discovered in GitLab EE Premium and...
Moderate severity
Unreviewed
Published
Feb 8, 2024
to the GitHub Advisory Database
•
Updated Oct 3, 2024
Description
Published by the National Vulnerability Database
Feb 8, 2024
Published to the GitHub Advisory Database
Feb 8, 2024
Last updated
Oct 3, 2024
An issue has been discovered in GitLab EE Premium and Ultimate affecting versions 16.4.3, 16.5.3, and 16.6.1. In projects using subgroups to define who can push and/or merge to protected branches, there may have been instances in which subgroup members with the Developer role were able to push or merge to protected branches.
References