Improper Authorization in GitLab Enterprise Edition - #VU54568

 

Improper Authorization in GitLab Enterprise Edition - #VU54568

Published: July 6, 2021


Vulnerability identifier: #VU54568
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass implemented security restrictions.

The vulnerability exists within the Single Sign-On  feature. The application allows new users to be created via single sign on despite user cap being enabled.


Affected software

GitLab Enterprise Edition

Remediation

Install updates from vendor's website.

GitLab Enterprise Edition - addressed in versions 13.11.6, 13.12.6, 14.0.2

External References

Related Security Bulletins