CVE-2025-0605Weak Authentication in Gitlab

Severity
4.3MEDIUMNVD
EPSS
0.1%
top 84.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 22

Description

An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group access controls could allow certain users to bypass two-factor authentication requirements.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages5 packages

CVEListV5gitlab/gitlab16.817.10.7+2
NVDgitlab/gitlab16.8.017.10.7+2
debiandebian/gitlab
gitlabgitlab/gitlab

🔴Vulnerability Details

2
GHSA
GHSA-v9g5-36x8-7xmx: An issue has been discovered in GitLab CE/EE affecting all versions from 162025-05-22
OSV
CVE-2025-0605: An issue has been discovered in GitLab CE/EE affecting all versions from 162025-05-22

📋Vendor Advisories

2
GitLab
CVE-2025-0605: An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group acce2025-05-22
Debian
CVE-2025-0605: gitlab - An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 be...2025