An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridden without appropriate permissions.
{ "versions": [ { "introduced": "12.0.0" }, { "fixed": "12.0.4" }, { "introduced": "12.1.0" }, { "fixed": "12.1.2" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-5474.json"
[ { "events": [ { "introduced": "11.8.0" }, { "fixed": "11.11.6" } ] } ]