CVE-2018-8971: Input Validation
The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, and 10.5.x before 10.5.6 has an incorrect omniauth-auth0 configuration, leading to signing in unintended users.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/gitlabto a version that resolves this vulnerability.Fixed in 16.0.8+ds1-2 - Upgrade
Upgrade
GitLab Auth0 integrationto a version that resolves this vulnerability.Fixed in 10.3.9 - Upgrade
Upgrade
GitLab Auth0 integrationto a version that resolves this vulnerability.Fixed in 10.4.6 - Upgrade
Upgrade
GitLab Auth0 integrationto a version that resolves this vulnerability.Fixed in 10.5.6
Event History
Frequently Asked Questions
What is the severity of CVE-2018-8971?
CVE-2018-8971 is classified as a critical vulnerability due to its potential to allow unintended users to sign in.
How do I fix CVE-2018-8971?
To fix CVE-2018-8971, upgrade GitLab to version 10.3.9, 10.4.6, 10.5.6 or later.
Which versions of GitLab are affected by CVE-2018-8971?
CVE-2018-8971 affects GitLab versions before 10.3.9, 10.4.x before 10.4.6, and 10.5.x before 10.5.6.
What systems are impacted by CVE-2018-8971?
CVE-2018-8971 impacts Debian systems running GitLab versions prior to the fixed releases.
How can I check if my GitLab installation is vulnerable to CVE-2018-8971?
You can check your GitLab version against the listed affected versions to determine if you are vulnerable to CVE-2018-8971.