> The upshot of all this is that admins who enabled some form of two-factor authentication (2FA) in GitLab are safe and unaffected by the vulnerability. And of course you enabled 2FA, didn't you?
...which begs the question: What US federal agencies aren't deploying their GitLab instances behind CAC auth at a minimum?