CRITICAL
CVE-2020-13300
CVSS
10
Description
GitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorization flow.
Summary dbcve.org
GitLab CE/EE versions 13.3 before 13.3.4 contained an OAuth authorization flaw allowing scope changes without user consent during the authorization flow. An attacker could manipulate the OAuth scope parameter mid-authorization to request additional permissions the user did not initially approve, potentially gaining unauthorized access to resources.
Mitigation
Upgrade GitLab to version 13.3.4 or later. Review existing OAuth authorizations for any unexpected scope grants and consider revoking and re-authorizing sensitive integrations.
Weakness (CWE)
CWE-863
Incorrect Authorization
EPSS Score
1.29%
Probability of exploitation in next 30 days
69th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.