CVE-2025-0605

An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group access controls could allow certain users to bypass two-factor authentication requirements.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.6 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
GitLabCNA
4.6 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 3%
VendorProductVersion
gitlabgitlab
16.8.0 ≤
𝑥
< 17.10.7
gitlabgitlab
16.8.0 ≤
𝑥
< 17.10.7
gitlabgitlab
17.11.0 ≤
𝑥
< 17.11.3
gitlabgitlab
17.11.0 ≤
𝑥
< 17.11.3
gitlabgitlab
18.0.0
gitlabgitlab
18.0.0
𝑥
= Vulnerable software versions