CRITICAL

CVE-2019-12428

Gitlab GitLab 2020-03-10 CVSS v3.1
CVSS
9.8

Description

An issue was discovered in GitLab Community and Enterprise Edition 6.8 through 11.11. Users could bypass the mandatory external authentication provider sign-in restrictions by sending a specially crafted request. It has Improper Authorization.

Summary dbcve.org

GitLab Community and Enterprise Edition versions 6.8 through 11.11 contained an improper authorization vulnerability where users could bypass mandatory external authentication provider sign-in restrictions by sending specially crafted requests. This allowed attackers to potentially access the GitLab instance without proper authentication through the configured external identity provider.

Mitigation

Upgrade GitLab to version 11.12 or later to patch this authorization bypass. Review authentication logs for unauthorized access attempts during the vulnerable period.

EPSS Score

1.35%
Probability of exploitation in next 30 days
70.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE