WebAuthn Bypass Vulnerability in GitLab CE/EE
CVE-2025-11984
6.8MEDIUM
What is CVE-2025-11984?
A security issue has been identified in GitLab CE/EE that permits an authenticated user to bypass WebAuthn two-factor authentication. This vulnerability arises from improper handling of session states, which can be exploited under specific conditions. Users are encouraged to upgrade to the latest versions of GitLab to mitigate this risk.
Affected Version(s)
GitLab 13.1 < 18.4.6
GitLab 18.5 < 18.5.4
GitLab 18.6 < 18.6.2
References
CVSS V3.1
Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Thanks [jcarre](https://hackerone.com/jcarre) for reporting this vulnerability through our HackerOne bug bounty program