← Back

CVE-2019-15585

nvd nist
Published: Jan 28, 2020Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Improper authentication exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) in the GitLab SAML integration had a validation issue that permitted an attacker to takeover another user's account.

Affected (6)

Products: Gitlab: Gitlab
1 product
Gitlab
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Gitlab
From 12.1.0 to 12.1.12
From 12.2.0 to 12.2.6
From 12.3.0 to 12.3.2
From 12.1.0 to 12.1.12
From 12.2.0 to 12.2.6
From 12.3.0 to 12.3.2

References (4)

Source: support@hackerone.com
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required

Timeline

No history available yet.