MEDIUM

CVE-2020-13294

Gitlab GitLab 2020-08-10 CVSS v3.1
CVSS
5.4

Description

In GitLab before 13.0.12, 13.1.6 and 13.2.3, access grants were not revoked when a user revoked access to an application.

Summary dbcve.org

In GitLab before 13.0.12, 13.1.6 and 13.2.3, when a user attempted to revoke an application's access through the UI, the OAuth access grants were not properly invalidated. This allowed applications to continue accessing user resources even after the user believed they had revoked access.

Mitigation

Upgrade GitLab to version 13.0.12, 13.1.6, 13.2.3 or later. After upgrading, verify that application access revocation now properly terminates active OAuth sessions.

EPSS Score

1.22%
Probability of exploitation in next 30 days
67.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE