vulnerability
Gitlab Gitlab: CVE-2019-5486: Authentication Bypass Using an Alternate Path or Channel
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
7 | (AV:N/AC:L/Au:S/C:P/I:P/A:P) | Dec 18, 2019 | Apr 22, 2025 | Apr 22, 2025 |
Severity
7
CVSS
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
Published
Dec 18, 2019
Added
Apr 22, 2025
Modified
Apr 22, 2025
Description
A authentication bypass vulnerability exists in GitLab CE/EE less thanv12.3.2, less thanv12.2.6, and less thanv12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements.
Solution
gitlab-gitlab-cve-2019-5486-solution

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.