CVE-2025-11984: Authentication Bypass Using an Alternate Path or Channel in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.1 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to bypass WebAuthn two-factor authentication by manipulating the session state under certain conditions.
Other sources
GitLab has remediated an issue that could have allowed an authenticated user to bypass WebAuthn two-factor authentication by manipulating the session state under certain conditions.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-11984?
CVE-2025-11984 is considered a critical vulnerability due to its potential to allow authenticated users to bypass WebAuthn two-factor authentication.
How do I fix CVE-2025-11984?
To remediate CVE-2025-11984, upgrade to GitLab versions 18.4.6, 18.5.4, or 18.6.2 or later.
What versions of GitLab are affected by CVE-2025-11984?
CVE-2025-11984 affects GitLab versions between 13.1 and 18.4.6, 18.5 and 18.5.4, and 18.6 and 18.6.2.
Who is primarily impacted by CVE-2025-11984?
Authenticated GitLab users using affected versions are primarily impacted by CVE-2025-11984.
What type of vulnerability is CVE-2025-11984?
CVE-2025-11984 is a security vulnerability related to authentication and session management.