Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an individual with existing knowledge of a victim's credential ID to bypass two-factor authentication by submitting forged device responses.
Problem types
CWE-252: Unchecked Return Value
Product status
18.6 (semver) before 18.6.4
18.7 (semver) before 18.7.2
18.8 (semver) before 18.8.2
Credits
Thanks [ahacker1](https://hackerone.com/ahacker1) for reporting this vulnerability through our HackerOne bug bounty program
References
gitlab.com/gitlab-org/gitlab/-/issues/585333 (GitLab Issue #585333)
hackerone.com/reports/3476052 (HackerOne Bug Bounty Report #3476052)
about.gitlab.com/...21/patch-release-gitlab-18-8-2-released/