Improper Authorization in GitLab Enterprise Edition - #VU54568
Published: July 6, 2021
Vulnerability identifier: #VU54568
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to bypass implemented security restrictions.
The vulnerability exists within the Single Sign-On feature. The application allows new users to be created via single sign on despite user cap being enabled.
Affected software
GitLab Enterprise Edition
Remediation
Install updates from vendor's website.
GitLab Enterprise Edition - addressed in versions 13.11.6, 13.12.6, 14.0.2