A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements.
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gitlab | Gitlab | * | 12.1.10 (excluding) |
Gitlab | Gitlab | 12.2.0 (including) | 12.2.6 (excluding) |
Gitlab | Gitlab | 12.3.0 (including) | 12.3.2 (excluding) |