logo

GitLab patches critical authentication bypass vulnerabilities

ID: 13e63b33-3020-59c2-9593-bdb7012c0014

STIX ID: report--13e63b33-3020-59c2-9593-bdb7012c0014

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-03-13

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

GitLab released patches for nine vulnerabilities affecting self-managed Community and Enterprise editions, notably two critical ruby-saml SAML SSO authentication bypasses (CVE-2025-25291, CVE-2025-25292) that allow an authenticated attacker with a signed SAML document to impersonate users within the same IdP, and a high-severity authenticated RCE (CVE-2025-27407) via the Direct Transfer feature; GitLab.com is already patched, but self-managed instances must upgrade to versions 17.9.2, 17.8.5, or 17.7.7 or apply recommended mitigations until patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.