Lucene search

K
cvelistHackeroneCVELIST:CVE-2019-15585
HistoryJan 28, 2020 - 2:21 a.m.

CVE-2019-15585

2020-01-2802:21:16
CWE-287
hackerone
www.cve.org

9.4 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

71.5%

Improper authentication exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) in the GitLab SAML integration had a validation issue that permitted an attacker to takeover another user’s account.

CNA Affected

[
  {
    "product": "Gitlab CE/EE",
    "vendor": "GitLab",
    "versions": [
      {
        "status": "affected",
        "version": "before 12.3.2"
      },
      {
        "status": "affected",
        "version": "before 12.2.6"
      },
      {
        "status": "affected",
        "version": "before 12.1.12"
      }
    ]
  }
]

9.4 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

71.5%

Related for CVELIST:CVE-2019-15585