It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 14.1.1 and above.
{
"severity": "Critical",
"cpes": [
"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*",
"cpe:2.3:a:gitlab:gitlab:14.3.0:*:*:*:community:*:*:*",
"cpe:2.3:a:gitlab:gitlab:14.3.0:*:*:*:enterprise:*:*:*",
"cpe:2.3:a:gitlab:gitlab:14.3.1:*:*:*:community:*:*:*",
"cpe:2.3:a:gitlab:gitlab:14.3.1:*:*:*:enterprise:*:*:*",
"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*"
]
}