GitLab 12.8.x before 12.8.6, when sign-up is enabled, allows remote attackers to bypass email domain restrictions within the two-day grace period for an unconfirmed email address.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Gitlab |
Gitlab |
12.8.0 (including) |
12.8.6 (excluding) |
References