CVE Vulnerabilities

CVE-2019-15585

Improper Authentication

Published: Jan 28, 2020 | Modified: Jan 29, 2020
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Improper authentication exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) in the GitLab SAML integration had a validation issue that permitted an attacker to takeover another users account.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 12.1.0 (including) 12.1.12 (excluding)
Gitlab Gitlab 12.2.0 (including) 12.2.6 (excluding)
Gitlab Gitlab 12.3.0 (including) 12.3.2 (excluding)
Gitlab Ubuntu esm-apps/xenial *
Gitlab Ubuntu upstream *
Gitlab Ubuntu xenial *

Potential Mitigations

References