GitLab CE
cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*, +1 more
- >= 16.4, < 17.5.5
- >= 17.6, < 17.6.3
- >= 17.7, < 17.7.1
A vulnerability exists in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 16.4 prior to 17.5.5, 17.6 prior to 17.6.3, and 17.7 prior to 17.7.1. The issue arises when users are created through the SAML provider; the external groups setting can override the external provider configuration. Consequently, users may not be designated as external, granting them access to internal projects or groups.
This vulnerability can lead to unauthorized access to internal projects or groups by users who should be marked as external.
To reproduce this vulnerability, configure a SAML provider on a GitLab instance and set it as an external provider. Then, establish SAML external groups without enabling the external attribute. When a user is created via the SAML provider, they may be incorrectly marked as internal instead of external, depending on their group membership.
GitLab has released versions 17.7.1, 17.6.3, and 17.5.5 that address this vulnerability. It is recommended to upgrade to one of these versions immediately.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.