CVE-2025-11865: Incorrect Authorization in GitLab
An issue has been discovered in GitLab EE affecting all versions from 18.1 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that, under certain circumstances, could have allowed an attacker to remove Duo flows of another user.
Other sources
GitLab has remediated an issue that, under certain circumstances, could have allowed a user to remove Duo flows of another user.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-11865?
CVE-2025-11865 is classified as a moderate severity vulnerability.
How do I fix CVE-2025-11865?
To fix CVE-2025-11865, upgrade to GitLab EE version 18.3.6, 18.4.4, or 18.5.2 or later.
What is the impact of CVE-2025-11865 on affected systems?
CVE-2025-11865 could allow an attacker to remove Duo flows of another user under specific circumstances.
Which versions of GitLab EE are affected by CVE-2025-11865?
CVE-2025-11865 affects GitLab EE versions from 18.1 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2.
Has GitLab released a fix for CVE-2025-11865?
Yes, GitLab has released a fix in versions 18.3.6, 18.4.4, and 18.5.2.