Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-1965
HistoryMay 03, 2023 - 9:15 p.m.

Default credentials

2023-05-0321:15:00
PRIOn knowledge base
www.prio-n.com
8
gitlab
unauthorized access
crafted url
verification
relaystate
access tokens
saml sso

AI Score

6.2

Confidence

High

EPSS

0.003

Percentile

65.5%

An issue has been discovered in GitLab EE affecting all versions starting from 14.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Lack of verification on RelayState parameter allowed a maliciously crafted URL to obtain access tokens granted for 3rd party Group SAML SSO logins. This feature isn’t enabled by default.

AI Score

6.2

Confidence

High

EPSS

0.003

Percentile

65.5%

Related for PRION:CVE-2023-1965