GitLab released emergency security updates across multiple CE and EE versions to fix CVE-2024-45409, a critical SAML authentication bypass affecting self-managed instances configured for SAML-based sign-in. The company said the issue was mitigated by updating omniauth-saml to 2.2.1 and ruby-saml to 1.17.0, and urged administrators to upgrade immediately to patched releases spanning the 17.x and 16.x branches. GitLab.com and GitLab Dedicated were already remediated and were not exposed in the same way.
GitLab also published mitigation and threat-hunting guidance for organizations that could not patch immediately, including enforcing GitLab two-factor authentication for all users and disabling the SAML two-factor bypass option. To help defenders identify attempted or successful exploitation, the advisories pointed to review of application_json and auth_json logs and shared Sigma-style detection ideas focused on anomalous extern_uid values and suspicious IP mismatches during authentication events.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
On 2024-09-17, GitLab released security patch versions 17.3.3, 17.2.7, 17.1.8, 17.0.8, and 16.11.10 to fix the critical SAML authentication bypass tracked as CVE-2024-45409. GitLab said GitLab.com and GitLab Dedicated were already remediated and urged self-managed customers using SAML to upgrade immediately.
On 2024-09-25, GitLab released multiple additional 16.x patch versions, including 16.10.10 through 16.0.10, to backport the security fix for the critical SAML authentication bypass CVE-2024-45409. The advisory noted the fix updated omniauth-saml to 2.2.1 and ruby-saml to 1.17.0, and included mitigation and log-hunting guidance for self-managed instances.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
docs.gitlab.com
Open sourcedocs.gitlab.com
Open sourceabout.gitlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.