Gitlab 14.9 Authentication Bypass
Posted by deepcore on April 27, 2022 – 3:21 am
Gitlab versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.7 prior to 14.7.7 suffer from a bypass vulnerability due to having set a hardcoded password for accounts registered using an OmniAuth provider.
Post a reply
You must be logged in to post a comment.