Total vulnerabilities in the database
The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, and 10.5.x before 10.5.6 has an incorrect omniauth-auth0 configuration, leading to signing in unintended users.
Software | From | Fixed in |
---|---|---|
gitlab / gitlab | - | 10.3.8.x |
gitlab / gitlab | 10.5.0 | 10.5.5.x |
gitlab / gitlab | 10.4.0 | 10.4.5.x |
debian / debian_linux | 9.0 | 9.0.x |