An issue was discovered in GitLab Community and Enterprise Edition 11.9.x and 11.10.x before 11.10.1. Merge requests created by email could be used to bypass push rules in certain situations.
{ "versions": [ { "introduced": "11.9.4" }, { "fixed": "11.10.1" }, { "introduced": "11.9.4" }, { "fixed": "11.10.1" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-15723.json"