It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 14.1.1 and above.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gitlab | Gitlab | 14.1.1 (including) | 14.1.7 (excluding) |
Gitlab | Gitlab | 14.2.0 (including) | 14.2.5 (excluding) |
Gitlab | Gitlab | 14.3.0 (including) | 14.3.0 (including) |
Gitlab | Gitlab | 14.3.1 (including) | 14.3.1 (including) |
Gitlab | Ubuntu | esm-apps/xenial | * |
Gitlab | Ubuntu | trusty | * |
Gitlab | Ubuntu | xenial | * |