HIGH

CVE-2020-13272

Gitlab GitLab 2020-06-19 CVSS v3.1
CVSS
8.8

Description

OAuth flow missing verification checks CE/EE 12.3 and later through 13.0.1 allows unverified user to use OAuth authorization code flow

Summary dbcve.org

This GitLab vulnerability involves missing verification checks in the OAuth authorization code flow that allow unverified users to authenticate via OAuth, potentially bypassing email verification requirements that should be enforced before permitting OAuth-based account creation or linking.

Mitigation

Upgrade to GitLab 13.0.2 or later, or apply the available security patches to ensure proper verification checks are enforced in the OAuth flow before allowing unverified users to complete authentication.

Weakness (CWE)

CWE-345

EPSS Score

0.58%
Probability of exploitation in next 30 days
46.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE