A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. In certain cases an invalid username could be accepted when 2FA is activated.
{
"versions": [
{
"introduced": "13.1.0"
},
{
"fixed": "13.1.10"
},
{
"introduced": "13.1.0"
},
{
"fixed": "13.1.10"
},
{
"introduced": "13.2.0"
},
{
"fixed": "13.2.8"
},
{
"introduced": "13.2.0"
},
{
"fixed": "13.2.8"
},
{
"introduced": "13.3.0"
},
{
"fixed": "13.3.4"
},
{
"introduced": "13.3.0"
},
{
"fixed": "13.3.4"
}
]
}