Related Vulnerabilities: CVE-2021-39909  

Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE since version 11.3 allows an attacker to bypass CODEOWNERS Merge Request approval requirement under rare circumstances.

Severity Medium

Remote Yes

Type Access restriction bypass

Description

Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE since version 11.3 allows an attacker to bypass CODEOWNERS Merge Request approval requirement under rare circumstances.

AVG-2503 gitlab 14.3.3-1 Medium Vulnerable

https://about.gitlab.com/releases/2021/10/28/security-release-gitlab-14-4-1-released/