This content is viewable by Everyone
Critical Vulnerability in GitLab Community Edition (CE) and Enterprise Edition (EE)
GitLab released security updates to address a Critical vulnerability in self-managed installations of the GitLab Community Edition (CE) and Enterprise Edition (EE). An unauthenticated attacker with access to any signed saml document (by the IdP) can forge a SAML Response/Assertion with arbitrary contents. This would allow the attacker to log in as an arbitrary user within the vulnerable system.
For a complete description of the vulnerabilities and affected systems go to ID VMSA-2024-0019.
IT Security