(CVE-2025-25291, CVE-2025-25292) allow SAML authentication bypass (CVSS 8.8). Update to versions 1.12.4 or 1.18.0 now.
GitLab released security updates for Community Edition (CE) and Enterprise Edition (EE), fixing nine vulnerabilities, among which two critical severity ruby-saml library authentication bypass flaws.
However, systems are only vulnerable if authentication via SAML SSO is active and attackers have already taken over a user account. The errors can be found in the ruby-saml library that Gitlab ...
GitLab released security updates for Community Edition (CE) and Enterprise Edition (EE), fixing nine vulnerabilities, among which two critical severity ruby-saml library authentication bypass flaws.
一些您可能无法访问的结果已被隐去。
显示无法访问的结果