MEDIUM
CVE-2020-13294
CVSS
5.4
Description
In GitLab before 13.0.12, 13.1.6 and 13.2.3, access grants were not revoked when a user revoked access to an application.
Summary dbcve.org
In GitLab before 13.0.12, 13.1.6 and 13.2.3, when a user attempted to revoke an application's access through the UI, the OAuth access grants were not properly invalidated. This allowed applications to continue accessing user resources even after the user believed they had revoked access.
Mitigation
Upgrade GitLab to version 13.0.12, 13.1.6, 13.2.3 or later. After upgrading, verify that application access revocation now properly terminates active OAuth sessions.
EPSS Score
1.22%
Probability of exploitation in next 30 days
67.4th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.