GitLab Warns of Max Severity Authentication Bypass Bug
ID: 218ccd52-a1e2-5c54-ad62-45412b7e05f3
STIX ID: report--218ccd52-a1e2-5c54-ad62-45412b7e05f3
Feed Name: Dark Reading
Threat Score
**Executive Summary:** A maximum-severity (CVSS 10.0) authentication bypass in GitLab's SAML integration (CVE-2024-45409) allows forged SAML assertions to authenticate as arbitrary users on affected self-managed instances, risking source-code theft, pipeline tampering, secret exfiltration, and other malicious actions; GitLab has patched managed instances and urges immediate updates for self-hosted installations and recommends multi-factor authentication and hunting guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
