CVE-2018-8971Improper Input Validation in Gitlab

Severity
9.8CRITICALNVD
EPSS
0.2%
top 60.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 24
Latest updateMay 14

Description

The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, and 10.5.x before 10.5.6 has an incorrect omniauth-auth0 configuration, leading to signing in unintended users.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

debiandebian/gitlab< gitlab 10.5.6+dfsg-1 (sid)
NVDgitlab/gitlab10.4.010.4.5+2
gitlabgitlab/gitlab

Also affects: Debian Linux 9.0

🔴Vulnerability Details

2
GHSA
GHSA-8c6r-xvww-2p23: The Auth0 integration in GitLab before 102022-05-14
OSV
CVE-2018-8971: The Auth0 integration in GitLab before 102018-03-24

📋Vendor Advisories

2
GitLab
CVE-2018-8971: The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, and 10.5.x before 10.5.6 has an incorrect omniauth-auth0 configuration, leading t2018-03-24
Debian
CVE-2018-8971: gitlab - The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, and 10.5.x ...2018