CVE-2018-8971
24.03.2018, 21:29
The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, and 10.5.x before 10.5.6 has an incorrect omniauth-auth0 configuration, leading to signing in unintended users.Enginsight
Vendor | Product | Version |
---|---|---|
gitlab | gitlab | 𝑥 ≤ 10.3.8 |
gitlab | gitlab | 10.4.0 ≤ 𝑥 ≤ 10.4.5 |
gitlab | gitlab | 10.5.0 ≤ 𝑥 ≤ 10.5.5 |
debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration