CVE-2019-15585: Critical severity gitlab vulnerability
Improper authentication exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) in the GitLab SAML integration had a validation issue that permitted an attacker to takeover another user's account.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-15585?
CVE-2019-15585 has a severity rating of high due to its potential to allow account takeover via improper authentication in GitLab's SAML integration.
How do I fix CVE-2019-15585?
To fix CVE-2019-15585, upgrade GitLab to version 12.3.2 or later, or to version 12.2.6 or later, or to version 12.1.12 or later.
What versions of GitLab are affected by CVE-2019-15585?
CVE-2019-15585 affects GitLab Community Edition and Enterprise Edition versions prior to 12.3.2, 12.2.6, and 12.1.12.
What does CVE-2019-15585 exploit?
CVE-2019-15585 exploits a validation issue in GitLab's SAML integration which can allow an attacker to take over another user's account.
Who is at risk for CVE-2019-15585?
Users of affected versions of GitLab Community and Enterprise Editions are at risk for CVE-2019-15585 if they have enabled SAML integration.