GitLab releases fix for critical SAML authentication bypass flaw
ID: cb5aadd3-0a41-545d-9d8f-851c31c9e4ea
STIX ID: report--cb5aadd3-0a41-545d-9d8f-851c31c9e4ea
Feed Name: Bleeping Computer
GitLab released patches addressing CVE-2024-45409, a critical SAML authentication bypass in OmniAuth-SAML/Ruby-SAML that can let an attacker craft malicious SAML responses to gain access to self-managed GitLab instances; affected versions and fixed releases are listed, and immediate mitigations include upgrading, enabling 2FA, and disallowing SAML 2FA bypass. GitLab also published signs of attempted or successful exploitation (RubySaml::ValidationError logs, unusual extern_uid values, missing SAML fields, multiple extern_uid for a user, unfamiliar IPs) but has not confirmed in-the-wild exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
