Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2019-15723

Description

An issue was discovered in GitLab Community and Enterprise Edition 11.9.x and 11.10.x before 11.10.1. Merge requests created by email could be used to bypass push rules in certain situations.

POC

Reference

- https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/

Github

- https://github.com/20142995/nuclei-templates

- https://github.com/cyb3r-w0lf/nuclei-template-collection