{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "versions": [
              {
                "introduced": "0"
              },
              {
                "last_affected": "8.13.0"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "8.13.0"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "8.13.1"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "8.13.1"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "8.13.2"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "8.13.2"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "8.13.3"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "8.13.3"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "8.13.4"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "8.13.4"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "8.13.5"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "8.13.5"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "8.13.6"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "8.13.6"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "8.13.7"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "8.13.7"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "8.14.0"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "8.14.0"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "8.14.1"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "8.14.1"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "8.14.2"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "8.14.2"
              }
            ]
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "last_affected": "294482f38388542b43b908dcb427759544a7486f"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "294482f38388542b43b908dcb427759544a7486f"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "3f76553a7cb877669deb10c5b0031e2aae1f7d9e"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "3f76553a7cb877669deb10c5b0031e2aae1f7d9e"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "507ff239d58e634e56b8012d965374702e938f60"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "507ff239d58e634e56b8012d965374702e938f60"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "966f6c7f5e501b6ff1af675b28bfa1d4a9d4e4d5"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "966f6c7f5e501b6ff1af675b28bfa1d4a9d4e4d5"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "7f1ed36b715e336174699ea696d29c88b31d2fea"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "7f1ed36b715e336174699ea696d29c88b31d2fea"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "94cc667f4ad84bfedf8714db7e8b4ba6acbb1f9a"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "94cc667f4ad84bfedf8714db7e8b4ba6acbb1f9a"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "4d6fd7481dfb1c71864bce2bffeb1b4990b1a854"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "4d6fd7481dfb1c71864bce2bffeb1b4990b1a854"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "bda1e862dca10dffbd31c272b01a93346e585e47"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "bda1e862dca10dffbd31c272b01a93346e585e47"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "4ae57e0b374bbb8e461305d8a7a68b550bdd768d"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "4ae57e0b374bbb8e461305d8a7a68b550bdd768d"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "ec3e70625ca648a7ba2aa11a5edbf712bbddd1e3"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "ec3e70625ca648a7ba2aa11a5edbf712bbddd1e3"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "b4c40a51ff743f788443bd431d76f6a765797216"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "b4c40a51ff743f788443bd431d76f6a765797216"
            }
          ],
          "repo": "https://gitlab.com/gitlab-org/gitlab",
          "type": "GIT"
        }
      ]
    }
  ],
  "details": "Multiple versions of GitLab expose a dangerous method to any authenticated user that could lead to the deletion of all Issue and MergeRequest objects on a GitLab instance. For GitLab instances with publicly available projects this vulnerability could be exploited by an unauthenticated user. A fix was included in versions 8.14.3, 8.13.8, and 8.12.11, which were released on December 5th 2016 at 3:59 PST. The GitLab versions vulnerable to this are 8.13.0, 8.13.0-ee, 8.13.1, 8.13.1-ee, 8.13.2, 8.13.2-ee, 8.13.3, 8.13.3-ee, 8.13.4, 8.13.4-ee, 8.13.5, 8.13.5-ee, 8.13.6, 8.13.6-ee, 8.13.7, 8.14.0, 8.14.0-ee, 8.14.1, 8.14.2, and 8.14.2-ee.",
  "id": "CVE-2016-9469",
  "modified": "2026-04-01T23:09:06.404838199Z",
  "published": "2017-03-28T02:59:01.247Z",
  "references": [
    {
      "type": "FIX",
      "url": "https://about.gitlab.com/2016/12/05/cve-2016-9469/"
    },
    {
      "type": "FIX",
      "url": "https://gitlab.com/gitlab-org/gitlab-ce/commit/29ceb98b5162677601702704e89d845580372078"
    },
    {
      "type": "FIX",
      "url": "https://gitlab.com/gitlab-org/gitlab-ce/commit/55196497301eea429913f9c4b1b37c42c2e358ce"
    },
    {
      "type": "FIX",
      "url": "https://gitlab.com/gitlab-org/gitlab-ce/commit/f325e4e734e5e486f3b02db176eb629124052b43"
    },
    {
      "type": "EVIDENCE",
      "url": "https://gitlab.com/gitlab-org/gitlab-ce/issues/25064"
    },
    {
      "type": "EVIDENCE",
      "url": "https://hackerone.com/reports/186194"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L",
      "type": "CVSS_V3"
    }
  ]
}