Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-5486

Опубликовано: 18 дек. 2019
Источник: debian
EPSS Низкий

Описание

A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gitlabfixed12.6.8-3package

Примечания

  • https://hackerone.com/reports/617896

  • https://about.gitlab.com/releases/2019/09/30/security-release-gitlab-12-dot-3-dot-2-released/

EPSS

Процентиль: 12%
0.00042
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 5 лет назад

A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements.

CVSS3: 8.8
nvd
больше 5 лет назад

A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements.

github
около 3 лет назад

A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements.

EPSS

Процентиль: 12%
0.00042
Низкий