Missing Authorization in GitLab
A vulnerability has been discovered in GitLab CE/EE affecting all versions starting with 16.8 before 18.5.0 that could have allowed unauthorized edits to merge request approval rules under certain conditions.
Affected products
- <18.5.0
Matching in nixpkgs
pkgs.gitlab
GitLab Community Edition
-
nixos-25.05 -
- nixos-25.05-small 18.2.1
pkgs.gitlab-ee
GitLab Enterprise Edition
-
nixos-25.05 -
- nixos-25.05-small 18.2.1
pkgs.gitlab-duo
CLI for GitLab AI assistant
pkgs.gitlab-kas
Kubernetes Agent (Gitlab side)
pkgs.gitlab-ci-ls
GitLab CI Language Server (gitlab-ci-ls)
-
nixos-25.05 -
- nixos-25.05-small 1.0.5
pkgs.gitlab-pages
Daemon used to serve static websites for GitLab users
-
nixos-25.05 -
- nixos-25.05-small 18.2.1
pkgs.gitlab-shell
SSH access and repository management app for GitLab
-
nixos-25.05 -
- nixos-25.05-small 14.43.0
pkgs.danger-gitlab
Gem that exists to ensure all dependencies are set up for Danger with GitLab
-
nixos-25.05 -
- nixos-25.05-small 8.0.0
pkgs.gitlab-clippy
Convert clippy warnings into GitLab Code Quality report
-
nixos-25.05 -
- nixos-25.05-small 1.0.3
pkgs.gitlab-runner
GitLab Runner the continuous integration executor of GitLab
-
nixos-25.05 -
- nixos-25.05-small 18.1.2
pkgs.gitlab-triage
GitLab's issues and merge requests triage, automated
-
nixos-25.05 -
- nixos-25.05-small 1.23.1
pkgs.gitlab-ci-local
Run gitlab pipelines locally as shell executor or docker executor
-
nixos-25.05 -
- nixos-25.05-small 4.59.0
pkgs.gitlab-timelogs
CLI utility to support you with your time logs in GitLab
-
nixos-25.05 -
- nixos-25.05-small 0.5.0
pkgs.gitlab-ci-linter
.gitlab-ci.yml lint helper tool
pkgs.gitlab-workhorse
None
-
nixos-25.05 -
- nixos-25.05-small 18.2.1
pkgs.gitlab-release-cli
Toolset to create, retrieve and update releases on GitLab
-
nixos-25.05 -
- nixos-25.05-small 0.23.0
pkgs.ocamlPackages.gitlab
Native OCaml bindings to Gitlab REST API v4
pkgs.vimPlugins.gitlab-vim
Integrate GitLab Duo with Neovim
-
nixos-25.05 -
- nixos-25.05-small 0.1.1
pkgs.gitlab-container-registry
GitLab Docker toolset to pack, ship, store, and deliver content
-
nixos-25.05 -
- nixos-25.05-small 4.25.0
pkgs.ocamlPackages.gitlab-jsoo
Gitlab APIv4 JavaScript library
pkgs.ocamlPackages.gitlab-unix
Gitlab APIv4 Unix library
pkgs.rubyPackages.gitlab-markup
None
pkgs.ocamlPackages_latest.gitlab
Native OCaml bindings to Gitlab REST API v4
pkgs.gitlab-elasticsearch-indexer
Indexes Git repositories into Elasticsearch for GitLab
-
nixos-25.05 -
- nixos-25.05-small 5.7.0
pkgs.haskellPackages.gitlab-haskell
A Haskell library for the GitLab web API
-
nixos-25.05 -
- nixos-25.05-small 1.0.2.2
pkgs.rubyPackages_3_3.gitlab-markup
None
-
nixos-25.05 -
- nixos-25.05-small 2.0.0
pkgs.rubyPackages_3_4.gitlab-markup
None
-
nixos-25.05 -
- nixos-25.05-small 2.0.0
pkgs.rubyPackages_3_5.gitlab-markup
None
-
nixos-25.11 -
- nixpkgs-25.11-darwin 2.0.0
pkgs.rubyPackages_4_0.gitlab-markup
None
-
nixos-25.11 2.0.0
pkgs.python312Packages.mkdocs-gitlab
MkDocs plugin to transform strings such as #1234, %56, or !789 into links to a Gitlab repository
pkgs.python312Packages.python-gitlab
Interact with GitLab API
pkgs.python313Packages.mkdocs-gitlab
MkDocs plugin to transform strings such as #1234, %56, or !789 into links to a Gitlab repository
-
nixos-25.05 -
- nixos-25.05-small 0.1.4
pkgs.python313Packages.python-gitlab
Interact with GitLab API
-
nixos-25.05 -
- nixos-25.05-small 5.6.0
pkgs.python314Packages.mkdocs-gitlab
MkDocs plugin to transform strings into links to a Gitlab repository
pkgs.python314Packages.python-gitlab
Interact with GitLab API
pkgs.ocamlPackages_latest.gitlab-jsoo
Gitlab APIv4 JavaScript library
pkgs.ocamlPackages_latest.gitlab-unix
Gitlab APIv4 Unix library
pkgs.terraform-providers.gitlabhq_gitlab
None
pkgs.prometheus-gitlab-ci-pipelines-exporter
Prometheus / OpenMetrics exporter for GitLab CI pipelines insights
-
nixos-25.05 -
- nixos-25.05-small 0.5.10
pkgs.vscode-extensions.gitlab.gitlab-workflow
GitLab extension for Visual Studio Code
-
nixos-25.05 -
- nixos-25.05-small 6.13.1
pkgs.perlPackages.AlienBuildPluginDownloadGitLab
Alien::Build plugin to download from GitLab
pkgs.perl5Packages.AlienBuildPluginDownloadGitLab
Alien::Build plugin to download from GitLab
-
nixos-unstable -
- nixpkgs-unstable 0.01
pkgs.perl538Packages.AlienBuildPluginDownloadGitLab
Alien::Build plugin to download from GitLab
pkgs.perl540Packages.AlienBuildPluginDownloadGitLab
Alien::Build plugin to download from GitLab
-
nixos-25.05 -
- nixos-25.05-small 0.01
Package maintainers
-
@balsoft Alexander Bantyev <balsoft75@gmail.com>
-
@yayayayaka Yaya <github@uwu.is>
-
@talyz Kim Lindberger <kim.lindberger@gmail.com>
-
@leona-ya Leona Maroni <nix@leona.is>
-
@globin Robin Gloster <mail@glob.in>
-
@krav Kristoffer Thømt Ravneberg <kristoffer@microdisko.no>
-
@pineapplehunter Shogo Takata <peshogo+nixpkgs@gmail.com>
-
@Ma27 Maximilian Bosch <maximilian@mbosch.me>
-
@wucke13 Wucke <wucke13@gmail.com>
-
@blitz Julian Stecklina <js@alien8.de>
-
@xanderio Alexander Sieg <alex@xanderio.de>
-
@snue Stefan Nuernberger <kabelfrickler@gmail.com>
-
@kilimnik Daniel Kilimnik <mail@kilimnik.de>
-
@zimbatm zimbatm <zimbatm@zimbatm.com>
-
@phip1611 Philipp Schuster <phip1611@gmail.com>
-
@mvisonneau Maxime VISONNEAU <maxime@visonneau.fr>
-
@mmahut Marek Mahut <marek.mahut@gmail.com>
-
@snpschaaf Philippe Schaaf <philipe.schaaf@secunet.com>
-
@nyanloutre Paul Trehiou <paul@nyanlout.re>
-
@caniko Can H. Tartanoglu <gpg@rotas.mozmail.com>
-
@zazedd Leonardo Santos <leomendesantos@gmail.com>
-
@yajo Jairo Llopis <yajo.sk8@gmail.com>