First published: Sat Mar 24 2018(Updated: )
The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, and 10.5.x before 10.5.6 has an incorrect omniauth-auth0 configuration, leading to signing in unintended users.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/gitlab | 16.0.8+ds1-2 | |
GitLab | <=10.3.8 | |
GitLab | >=10.4.0<=10.4.5 | |
GitLab | >=10.5.0<=10.5.5 | |
Debian Debian Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8971 is classified as a critical vulnerability due to its potential to allow unintended users to sign in.
To fix CVE-2018-8971, upgrade GitLab to version 10.3.9, 10.4.6, 10.5.6 or later.
CVE-2018-8971 affects GitLab versions before 10.3.9, 10.4.x before 10.4.6, and 10.5.x before 10.5.6.
CVE-2018-8971 impacts Debian systems running GitLab versions prior to the fixed releases.
You can check your GitLab version against the listed affected versions to determine if you are vulnerable to CVE-2018-8971.