An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Improper XPath validation allows modified SAML response to bypass 2FA requirement under specialized conditions.
Solution:
The product receives a complex input with multiple elements or fields that must be consistent with each other, but it does not validate or incorrectly validates that the input is actually consistent.
Link | Tags |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/507445 | permissions required issue tracking |
https://hackerone.com/reports/2851261 | technical description permissions required exploit |