CRITICAL
CVE-2020-13292
CVSS
9.6
Description
In GitLab before 13.0.12, 13.1.6 and 13.2.3, it is possible to bypass E-mail verification which is required for OAuth Flow.
Summary dbcve.org
This vulnerability allows bypassing email verification during the OAuth authentication flow in GitLab. An attacker could potentially associate unverified emails with their OAuth account or bypass verification checks meant to ensure users control the email address they're authenticating with.
Mitigation
Upgrade GitLab to version 13.0.12, 13.1.6, 13.2.3 or later to apply the patch for this OAuth email verification bypass.
Weakness (CWE)
CWE-287
Improper Authentication
EPSS Score
1%
Probability of exploitation in next 30 days
61.2th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.