VYPR
High severity8.0NVD Advisory· Published Sep 14, 2020· Updated Jun 17, 2026

CVE-2020-13300

CVE-2020-13300

Description

GitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorization flow.

Affected products

5
  • GitLab Inc./GitLabv53 versions
    >=13.3, <13.3.4+ 2 more
    • (no CPE)range: >=13.3, <13.3.4
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=13.3.0,<13.3.4
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=13.3.0,<13.3.4
  • Range: <13.3.4
  • osv-coords
    Range: >= 13.3.0, < 13.3.4

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.