CRITICAL
CVE-2020-13312
CVSS
9.8
Description
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab OAuth endpoint was vulnerable to brute-force attacks through a specific parameter.
Summary dbcve.org
GitLab's OAuth implementation contains a vulnerability where a specific parameter on the OAuth endpoint is susceptible to brute-force attacks. An attacker could exploit this by making repeated requests with different values to guess or cycle through authentication tokens, potentially leading to unauthorized access to user accounts via the OAuth flow.
Mitigation
Upgrade GitLab to version 13.1.10, 13.2.8, 13.3.4 or later. These versions contain the fix for the OAuth brute-force vulnerability.
Weakness (CWE)
CWE-307
EPSS Score
0.85%
Probability of exploitation in next 30 days
56.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.