Description
A vulnerability has been discovered in GitLab CE/EE affecting all versions starting with 16.8 before 18.5.0 that could have allowed unauthorized edits to merge request approval rules under certain conditions.
Problem types
CWE-862: Missing Authorization
Product status
16.8 (semver) before 18.5.0
Credits
Thanks [theluci](https://hackerone.com/theluci) for reporting this vulnerability through our HackerOne bug bounty program
References
gitlab.com/gitlab-org/gitlab/-/issues/519340 (GitLab Issue #519340)
hackerone.com/reports/2980839 (HackerOne Bug Bounty Report #2980839)