vulnerability

Gitlab Gitlab: CVE-2019-5486: Authentication Bypass Using an Alternate Path or Channel

Severity
7
CVSS
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
Published
Dec 18, 2019
Added
Apr 22, 2025
Modified
Apr 22, 2025

Description

A authentication bypass vulnerability exists in GitLab CE/EE less thanv12.3.2, less thanv12.2.6, and less thanv12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements.

Solution

gitlab-gitlab-cve-2019-5486-solution
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.