PT-2020-13441 · Gitlab · Gitlab Ce/Ee+1

Published

2020-09-14

·

Updated

2024-03-06

·

CVE-2020-13300

CVSS v3.1

8.0

High

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 13.3 through 13.3.3
Description The issue concerns an OAuth authorization scope change without user consent in the middle of the authorization flow.
Recommendations For GitLab CE/EE versions 13.3 through 13.3.3, update to version 13.3.4 or later to resolve the issue.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2020-13300
CVE-2020-13300

Affected Products

Gitlab
Gitlab Ce/Ee