logo

GitLab releases fix for critical SAML authentication bypass flaw

ID: cb5aadd3-0a41-545d-9d8f-851c31c9e4ea

STIX ID: report--cb5aadd3-0a41-545d-9d8f-851c31c9e4ea

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-09-18

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

GitLab released patches addressing CVE-2024-45409, a critical SAML authentication bypass in OmniAuth-SAML/Ruby-SAML that can let an attacker craft malicious SAML responses to gain access to self-managed GitLab instances; affected versions and fixed releases are listed, and immediate mitigations include upgrading, enabling 2FA, and disallowing SAML 2FA bypass. GitLab also published signs of attempted or successful exploitation (RubySaml::ValidationError logs, unusual extern_uid values, missing SAML fields, multiple extern_uid for a user, unfamiliar IPs) but has not confirmed in-the-wild exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.