InsighthubNews
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
Reading: GitLab fixes critical SAML authentication bypass vulnerability in CE and EE editions
Share
Font ResizerAa
InsighthubNewsInsighthubNews
Search
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
© 2024 All Rights Reserved | Powered by Insighthub News
InsighthubNews > Technology > GitLab fixes critical SAML authentication bypass vulnerability in CE and EE editions
Technology

GitLab fixes critical SAML authentication bypass vulnerability in CE and EE editions

September 19, 2024 3 Min Read
Share
Authentication Bypass
SHARE

GitLab has released a patch to address a critical flaw affecting Community Edition (CE) and Enterprise Edition (EE) that could lead to authentication bypass.

The vulnerability exists in the ruby-saml library (CVE-2024-45409, CVSS score: 10.0) and could allow an attacker to log in as any user on a vulnerable system. The issue was addressed by maintainers last week.

The issue occurs because the library doesn’t properly validate the signature of the SAML response. SAML stands for Security Assertion Markup Language, a protocol that enables single sign-on (SSO) and the exchange of authentication and authorization data between multiple apps and websites.

According to the security advisory, “An unauthenticated attacker with access to the signed (by the IdP) SAML document can forge a SAML response/assertion containing arbitrary content, allowing the attacker to log in as any user within the vulnerable system.”

It’s also worth noting that this flaw also affects omniauth-saml, which has released its own update (version 2.2.1) to upgrade ruby-saml to version 1.17.

GitLab’s latest patch is designed to update the dependencies omniauth-saml to version 2.2.1 and ruby-saml to 1.17.0, which includes versions 17.3.3, 17.2.7, 17.1.8, 17.0.8, and 16.11.10.

As a mitigation measure, GitLab strongly encourages users of self-managed installations to enable two-factor authentication (2FA) for all accounts and disallow the SAML two-factor bypass option.

While GitLab has not stated that this flaw has been exploited in the wild, it has shown signs of attempted and successful exploitation, suggesting that threat actors may be actively attempting to leverage the vulnerability to gain access to susceptible GitLab instances.

See also  The Solution is Cyber ​​Hygiene

“Successful attack attempts will trigger SAML-related log events,” the company said. “If an attack attempt is successful, the extern_id value set by the attacker attempting the attack will be logged.”

“When an exploit attempt fails, a ValidationError may be generated from the RubySaml library. This can happen for a variety of reasons related to the complexity of creating a working exploit.”

The development comes after the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a recently disclosed critical bug (CVE-2024-27348, CVSS score: 9.8) affecting Apache HugeGraph-Server, based on evidence of active exploitation.

Federal Civil Administration Entities (FCEBs) are recommended to fix identified vulnerabilities by October 9, 2024, to protect their networks against active threats.

Share This Article
Twitter Copy Link
Previous Article Anime Defense Special Code September 2024 Anime Defense Special Code September 2024
Next Article California voters are fed up with crime and apparent Democratic inaction. California voters are fed up with crime and apparent Democratic inaction.
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest News

The Solution is Cyber ​​Hygiene

The Solution is Cyber ​​Hygiene

Cybersecurity in healthcare has never been more urgent. As the…

September 19, 2024
mm

Enterprise LLM API: A top choice for powering LLM applications in 2024

Some big recent news stories have escalated the race for…

September 19, 2024
Authentication Bypass

GitLab fixes critical SAML authentication bypass vulnerability in CE and EE editions

GitLab has released a patch to address a critical flaw…

September 19, 2024
Chinese engineer indicted in US for years of cyberespionage targeting NASA and military

Chinese engineer indicted in US for years of cyberespionage targeting NASA and military

A Chinese national has been indicted in the United States…

September 19, 2024
IoT Botnet

New “Raptor Train” IoT Botnet Compromises Over 200,000 Devices Worldwide

Cybersecurity researchers have discovered a never-before-seen botnet made up of…

September 18, 2024

You Might Also Like

Global Syndicate
Technology

Singapore Police arrest six hackers linked to global cybercrime ring

3 Min Read
RustDoor Malware
Technology

North Korean hackers target LinkedIn cryptocurrency users with RustDoor malware

4 Min Read
Google Workspace
Technology

How to investigate ChatGPT activity in Google Workspace

5 Min Read
Goodbye to Phishing
Technology

A must-have to combat credential theft

6 Min Read
InsighthubNews
InsighthubNews

Welcome to InsighthubNews, your reliable source for the latest updates and in-depth insights from around the globe. We are dedicated to bringing you up-to-the-minute news and analysis on the most pressing issues and developments shaping the world today.

  • Home
  • Celebrity
  • Environment
  • Business
  • Crypto
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
  • World News
  • Politics
  • Technology
  • Sports
  • Gaming
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service

© 2024 All Rights Reserved | Powered by Insighthub News

Welcome Back!

Sign in to your account

Lost your password?