CVE-2019-5486: High severity gitlab vulnerability
A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-5486?
CVE-2019-5486 is considered a high severity vulnerability due to its potential for authentication bypass.
How do I fix CVE-2019-5486?
To fix CVE-2019-5486, upgrade GitLab to version 12.1.10 or later, or 12.2.6 or later, or 12.3.2 or later.
What type of vulnerability is CVE-2019-5486?
CVE-2019-5486 is an authentication bypass vulnerability found in the Salesforce login integration of GitLab.
What versions of GitLab are affected by CVE-2019-5486?
CVE-2019-5486 affects GitLab CE/EE versions prior to 12.1.10, 12.2.6, and 12.3.2.
Can CVE-2019-5486 allow unauthorized account creation?
Yes, CVE-2019-5486 can allow an attacker to create accounts that bypass domain restrictions and email verification.