GitLab has patched nine vulnerabilities affecting its Community Edition (CE) and Enterprise Edition (EE) solutions, and urged users to apply the patch immediately.
Among the nine flaws, two are critical severity vulnerabilities that allow threat actors to bypass authentication.
Users are advised to update their GitLab CE/EE to versions 17.7.7, 17.8.5, and 17.9.2 to mitigate the risks.
The critical flaws were discovered in the ruby-saml library and could lead to data exfiltration, privilege escalation, and more.