GitLab 12.8.x before 12.8.6, when sign-up is enabled, allows remote attackers to bypass email domain restrictions within the two-day grace period for an unconfirmed email address.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Gitlab | Gitlab | 12.8.0 (including) | 12.8.6 (excluding) |
References