ZeroHour

CVE-2024-12093

PoC
CVSS 3.1
6.8 medium
EPSS
<1%p38
Published
()
Modified
Description

An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Improper XPath validation allows modified SAML response to bypass 2FA requirement under specialized conditions.

Vendors
gitlab
Products
gitlab
Weakness
CWE-1288
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.