CVE Vulnerabilities

CVE-2025-0605

Weak Authentication

Published: May 22, 2025 | Modified: May 29, 2025
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group access controls could allow certain users to bypass two-factor authentication requirements.

Weakness

The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.

Affected Software

NameVendorStart VersionEnd Version
GitlabGitlab16.8.0 (including)17.10.7 (excluding)
GitlabGitlab17.11.0 (including)17.11.3 (excluding)
GitlabGitlab18.0.0 (including)18.0.0 (including)
GitlabUbuntuesm-apps/xenial*

Extended Description

Attackers may be able to bypass weak authentication faster and/or with less effort than expected.

References