
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8, and 13.3.4 that allowed bypassing two-factor authentication (2FA) requirements for groups. When 2FA was enabled for groups, malicious users could circumvent this security restriction by sending specific queries to the API endpoint (GitLab Release, NVD).
The vulnerability stemmed from improper validation of authentication requirements in GitLab's API endpoints. Users could bypass 2FA restrictions using either a session cookie for GET requests or a previously generated private token for both GET and POST requests. The issue affected all previous GitLab versions until the release of the patched versions (HackerOne Report).
This vulnerability allowed unauthorized access to group resources that should have been protected by 2FA requirements. Attackers could access and interact with group resources, including projects and their associated data, effectively rendering the 2FA group security setting ineffective (GitLab Issue).
The vulnerability could be exploited by using either a valid session cookie or a previously generated private token to make API requests. While GET requests were possible with session cookies, private tokens enabled both GET and POST requests, allowing for more extensive access to protected resources (HackerOne Report).
The vulnerability was patched in GitLab versions 13.1.10, 13.2.8, and 13.3.4. Organizations running affected versions were strongly recommended to upgrade to these patched versions immediately to prevent unauthorized access to group resources (GitLab Release).
The vulnerability was responsibly reported by security researcher xanbanx through GitLab's bug bounty program on HackerOne. GitLab addressed the issue promptly and included the fix in their security release (GitLab Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."