CyberzSOC

Publication detail
← Back to advisories & guidance

2024-101: Critical SAML Authentication Bypass in Gitlab ↗ source

September 19, 2024 CERT-EU Advisory

Summary

The vulnerability affects the Community Edition (CE) and the Enterprise Edition (EE) instances that utilise SAML for single sign-on (SSO) [1,2]. It is recommended updating affected servers as soon as possible, and searching for potential successful exploitation of the vulnerability in the logs. The vulnerability CVE-2024-45409, with a CVSS score of 10, arises from improper validation of SAML assertions, particularly the extern_uid , which uniquely identifies users. When a malicious SAML response is crafted, GitLab fails to verify critical elements in the SAML assertion, thus allowing the attacker to impersonate a legitimate user on the affected server. This vulnerability is due to issues in the OmniAuth-SAML and Ruby-SAML libraries.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-45409 10.0 Critical SAML-Toolkits ruby-saml The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.16.0 does not properly verify…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.