Improper Authentication in Gitlab Community Edition - CVE-2019-5486

 

Improper Authentication in Gitlab Community Edition - CVE-2019-5486

Published: December 18, 2019 / Updated: July 17, 2020


Vulnerability identifier: #VU30519
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-5486
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to execute arbitrary code.

A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements.


Affected software

Gitlab Community Edition

How to mitigate CVE-2019-5486

Install update from vendor's website.

Gitlab Community Edition - update to 12.3.2

External References

Related Security Bulletins