Описание
GitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorization flow.
Ссылки
- Vendor Advisory
- Broken Link
- Permissions RequiredThird Party Advisory
- Vendor Advisory
- Broken Link
- Permissions RequiredThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 13.3.0 (включая) до 13.3.4 (исключая)Версия от 13.3.0 (включая) до 13.3.4 (исключая)
Одно из
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
EPSS
Процентиль: 46%
0.00232
Низкий
8 High
CVSS3
10 Critical
CVSS3
6.4 Medium
CVSS2
Дефекты
CWE-863
Связанные уязвимости
CVSS3: 8
ubuntu
больше 5 лет назад
GitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorization flow.
CVSS3: 8
debian
больше 5 лет назад
GitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth a ...
CVSS3: 10
github
больше 3 лет назад
GitLab before version 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorization flow.
EPSS
Процентиль: 46%
0.00232
Низкий
8 High
CVSS3
10 Critical
CVSS3
6.4 Medium
CVSS2
Дефекты
CWE-863