An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridden without appropriate permissions.
| Software | From | Fixed in |
|---|---|---|
| gitlab / gitlab | 12.0.0 | 12.0.4 |
| gitlab / gitlab | 12.1.0 | 12.1.2 |
| gitlab / gitlab | 11.8.0 | 11.11.6 |