HIGH
CVE-2020-13272
CVSS
8.8
Description
OAuth flow missing verification checks CE/EE 12.3 and later through 13.0.1 allows unverified user to use OAuth authorization code flow
Summary dbcve.org
This GitLab vulnerability involves missing verification checks in the OAuth authorization code flow that allow unverified users to authenticate via OAuth, potentially bypassing email verification requirements that should be enforced before permitting OAuth-based account creation or linking.
Mitigation
Upgrade to GitLab 13.0.2 or later, or apply the available security patches to ensure proper verification checks are enforced in the OAuth flow before allowing unverified users to complete authentication.
Weakness (CWE)
CWE-345
EPSS Score
0.58%
Probability of exploitation in next 30 days
46.3th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.