Impact
GitLab has a missing authentication enforcement check that can allow an authenticated user to bypass SAML SSO sign‑in restrictions and authenticate without SSO. The flaw is a direct application of CWE-306, where an application does not verify that a user is authenticated before allowing access to a protected function. This bypass could enable an attacker who already has legitimate credentials to obtain access to resources that are intended to be protected by SAML SSO, potentially leading to unauthorized data access or modification.
Affected Systems
The vulnerability affects GitLab Community Edition and Enterprise Edition, all versions starting from 18.6 that are earlier than 19.1.8, all 19.2 releases before 19.2.6, and all 19.3 releases before 19.3.2. Upgrading to version 19.1.8, 19.2.6, 19.3.2, or later resolves the missing authentication enforcement issue.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity impact. The EPSS score of < 1% denotes a low likelihood that this vulnerability is actively exploited in the wild. It is not listed in the CISA KEV catalog, so there is no evidence of current widespread exploitation. Because the flaw allows an authenticated user to bypass SAML SSO enforcement, an attacker who has legitimate access credentials can avoid the SSO process and gain access to protected resources. The attack requires that the user exploits a specific context where the authentication check is omitted; the vendor notes that this occurs under certain conditions, so proactive access controls and monitoring are advisable.
OpenCVE Enrichment