CyberRota Analysis
AI-GeneratedGitLab CE/EE versions prior to 19.0.5, 19.1.3, and 19.2.1 are vulnerable to improper authorization checks, allowing authenticated users with developer-role permissions to commit changes to projects even after being removed as members. This could lead to unauthorized modifications to project content, posing a risk to project integrity. Organizations using affected versions should prioritize updating their GitLab installations to mitigate this low-severity vulnerability.
Original NVD Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to commit changes to a project after being removed as a member, due to improper authorization checks on merge request collaboration settings.
Related CVEs
Other vulnerabilities affecting the same vendor(s)