vulnerability
Gitlab Gitlab: CVE-2019-5486: Authentication Bypass Using an Alternate Path or Channel
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
7 | (AV:N/AC:L/Au:S/C:P/I:P/A:P) | 2019-12-18 | 2025-04-22 | 2025-04-22 |
Severity
7
CVSS
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
Published
2019-12-18
Added
2025-04-22
Modified
2025-04-22
Description
A authentication bypass vulnerability exists in GitLab CE/EE less thanv12.3.2, less thanv12.2.6, and less thanv12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements.
Solution
gitlab-gitlab-cve-2019-5486-solution

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.