logo

GitLab Warns of Max Severity Authentication Bypass Bug

ID: 218ccd52-a1e2-5c54-ad62-45412b7e05f3

STIX ID: report--218ccd52-a1e2-5c54-ad62-45412b7e05f3

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-09-19

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

**Executive Summary:** A maximum-severity (CVSS 10.0) authentication bypass in GitLab's SAML integration (CVE-2024-45409) allows forged SAML assertions to authenticate as arbitrary users on affected self-managed instances, risking source-code theft, pipeline tampering, secret exfiltration, and other malicious actions; GitLab has patched managed instances and urges immediate updates for self-hosted installations and recommends multi-factor authentication and hunting guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.