CRITICAL

CVE-2020-13300

Gitlab GitLab 2020-09-14 CVSS v3.1
CVSS
10

Description

GitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorization flow.

Summary dbcve.org

GitLab CE/EE versions 13.3 before 13.3.4 contained an OAuth authorization flaw allowing scope changes without user consent during the authorization flow. An attacker could manipulate the OAuth scope parameter mid-authorization to request additional permissions the user did not initially approve, potentially gaining unauthorized access to resources.

Mitigation

Upgrade GitLab to version 13.3.4 or later. Review existing OAuth authorizations for any unexpected scope grants and consider revoking and re-authorizing sensitive integrations.

Weakness (CWE)

CWE-863 Incorrect Authorization

EPSS Score

1.29%
Probability of exploitation in next 30 days
69th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE