Vulnerabilities > CVE-2020-13300 - Incorrect Authorization vulnerability in Gitlab 13.3.0/13.3.1/13.3.2

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
gitlab
CWE-863
critical

Summary

GitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorization flow.

Vulnerable Configurations

Part Description Count
Application
Gitlab
6

Common Weakness Enumeration (CWE)