CVE-2020-23355: Improper Authentication
(updated )
Codiad /componentss/user/class.user.php:Authenticate()
is vulnerable in magic hash authentication bypass. If encrypted or hash value for the passwords form certain formats of magic hash, e.g, 0e123
, another hash value 0e234
something can successfully authenticate.
References
Detect and mitigate CVE-2020-23355 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →