An issue was discovered in GitLab Community and Enterprise Edition 6.8 through 11.11. Users could bypass the mandatory external authentication provider sign-in restrictions by sending a specially crafted request. It has Improper Authorization.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gitlab | Gitlab | 6.8.0 (including) | 11.11.0 (including) |
Gitlab | Ubuntu | esm-apps/xenial | * |
Gitlab | Ubuntu | upstream | * |
Gitlab | Ubuntu | xenial | * |