CVE Vulnerabilities

CVE-2020-13272

Insufficient Verification of Data Authenticity

Published: Jun 19, 2020 | Modified: Jul 21, 2021
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

OAuth flow missing verification checks CE/EE 12.3 and later through 13.0.1 allows unverified user to use OAuth authorization code flow

Weakness

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 12.3.0 (including) 12.9.8 (excluding)
Gitlab Gitlab 12.10.0 (including) 12.10.7 (excluding)
Gitlab Gitlab 13.0.0 (including) 13.0.0 (including)

References