GitLab
cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*, +2 more
- >= 11.1, < 17.10.7
- >= 17.11, < 17.11.3
- >= 18.0, < 18.0.1
A vulnerability exists in GitLab CE/EE versions 11.1 prior to 17.10.7, 17.11 prior to 17.11.3, and 18.0 prior to 18.0.1. The issue arises from improper validation of XPath, which allows a modified SAML response to bypass the two-factor authentication (2FA) requirement under certain conditions.
Exploitation of this vulnerability allows for bypassing two-factor authentication, potentially leading to unauthorized access to user accounts.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.