First published: Sat Mar 24 2018(Updated: )
The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, and 10.5.x before 10.5.6 has an incorrect omniauth-auth0 configuration, leading to signing in unintended users.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/gitlab | 16.0.8+ds1-2 | |
GitLab GitLab | <=10.3.8 | |
GitLab GitLab | >=10.4.0<=10.4.5 | |
GitLab GitLab | >=10.5.0<=10.5.5 | |
Debian Debian Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.