An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Improper XPath validation allows modified SAML response to bypass 2FA requirement under specialized conditions.
Metrics
Affected Vendors & Products
References
History
Thu, 22 May 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 22 May 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Improper XPath validation allows modified SAML response to bypass 2FA requirement under specialized conditions. | |
Title | Improper Validation of Consistency within Input in GitLab | |
First Time appeared |
Gitlab
Gitlab gitlab |
|
Weaknesses | CWE-1288 | |
CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | |
Vendors & Products |
Gitlab
Gitlab gitlab |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitLab
Published: 2025-05-22T14:32:04.147Z
Updated: 2025-05-22T14:44:03.881Z
Reserved: 2024-12-03T11:02:06.764Z
Link: CVE-2024-12093

Updated: 2025-05-22T14:43:58.719Z

Status : Awaiting Analysis
Published: 2025-05-22T15:16:03.580
Modified: 2025-05-23T15:55:02.040
Link: CVE-2024-12093

No data.