Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication
{ "binaries": [ { "binary_version": "8.5.8+dfsg-5", "binary_name": "gitlab" } ] }