CVE-2018-8971: Debian Linux
Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.
The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, and 10.5.x before 10.5.6 has an incorrect omniauth-auth0 configuration, leading to signing in unintended users.
Affected products
- Debian Debian Linux: version 9.0 only
- GitLab GitLab: up to and including 10.3.8; from 10.4.0, up to and including 10.4.5; from 10.5.0, up to and including 10.5.5
Published 2018-03-24. Last modified 2026-06-17.