CVE-2025-0605: Weak Authentication in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group access controls could allow certain users to bypass two-factor authentication requirements.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-0605?
CVE-2025-0605 is considered a high-severity vulnerability due to its potential to allow unauthorized bypass of two-factor authentication.
How do I fix CVE-2025-0605?
To fix CVE-2025-0605, upgrade GitLab CE/EE to version 17.10.7, 17.11.3, or 18.0.1 or later.
What versions are affected by CVE-2025-0605?
CVE-2025-0605 affects all GitLab CE/EE versions from 16.8 to below 17.10.7, from 17.11 to below 17.11.3, and from 18.0 to below 18.0.1.
Who is impacted by CVE-2025-0605?
Users with group access in GitLab CE/EE could be impacted by CVE-2025-0605 if they are able to bypass two-factor authentication.
Is there a workaround for CVE-2025-0605?
No official workaround is recommended for CVE-2025-0605; upgrading to the patched versions is necessary to mitigate the risk.