vulnerability

Gitlab Gitlab: CVE-2019-5486: Authentication Bypass Using an Alternate Path or Channel

Severity
7
CVSS
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
Published
2019-12-18
Added
2025-04-22
Modified
2025-04-22

Description

A authentication bypass vulnerability exists in GitLab CE/EE less thanv12.3.2, less thanv12.2.6, and less thanv12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements.

Solution

gitlab-gitlab-cve-2019-5486-solution
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.