CRITICAL

CVE-2020-13312

Gitlab GitLab 2020-09-14 CVSS v3.1
CVSS
9.8

Description

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab OAuth endpoint was vulnerable to brute-force attacks through a specific parameter.

Summary dbcve.org

GitLab's OAuth implementation contains a vulnerability where a specific parameter on the OAuth endpoint is susceptible to brute-force attacks. An attacker could exploit this by making repeated requests with different values to guess or cycle through authentication tokens, potentially leading to unauthorized access to user accounts via the OAuth flow.

Mitigation

Upgrade GitLab to version 13.1.10, 13.2.8, 13.3.4 or later. These versions contain the fix for the OAuth brute-force vulnerability.

Weakness (CWE)

CWE-307

EPSS Score

0.85%
Probability of exploitation in next 30 days
56.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE