CVE-2025-0605 | GitLab Community Edition/Enterprise Edition up to 17.10.6/17.11.2/18.0.0 Two-Factor Authentication Requirements weak authentication (EUVD-2025-16150 / Nessus ID 237105)
A vulnerability has been found in GitLab Community Edition and Enterprise Edition up to 17.10.6/17.11.2/18.0.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Two-Factor Authentication Requirements. The manipulation leads to weak authentication.
This vulnerability is known as CVE-2025-0605. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.