GitLab
cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*, +2 more
- >= 16.8, < 17.10.7
- >= 17.11, < 17.11.3
- >= 18.0, < 18.0.1
A vulnerability exists in GitLab CE/EE versions 16.8 prior to 17.10.7, 17.11 prior to 17.11.3, and 18.0 prior to 18.0.1. This issue allows certain users to bypass two-factor authentication requirements due to flaws in group access controls.
Exploitation of this vulnerability could lead to unauthorized access by allowing users to bypass two-factor authentication, potentially enabling them to access sensitive information or perform actions that require higher security verification.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.