HIGH
CVE-2019-5486
CVSS
8.8
Description
A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements.
Weakness (CWE)
CWE-288
CWE-287
Improper Authentication
EPSS Score
1.51%
Probability of exploitation in next 30 days
73.3th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.