Improper Authentication in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2020-13292
Published: August 10, 2020
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in when processing authentication requests within the required email verification for the OAuth authorization code flow. A remote attacker can bypass authentication process and gain unauthorized access to the application.
Affected software
GitLab Enterprise Edition
How to mitigate CVE-2020-13292
GitLab Enterprise Edition - addressed in versions 13.0.12, 13.1.6, 13.2.3