CVE-2018-8971: Debian Linux

Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.

The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, and 10.5.x before 10.5.6 has an incorrect omniauth-auth0 configuration, leading to signing in unintended users.

Affected products

  • Debian Debian Linux: version 9.0 only
  • GitLab GitLab: up to and including 10.3.8; from 10.4.0, up to and including 10.4.5; from 10.5.0, up to and including 10.5.5

Published 2018-03-24. Last modified 2026-06-17.