CVE-2020-13300: GitLab

Critical severity, CVSS 10.0. EPSS: 1.3% chance of exploitation in the next 30 days.

GitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorization flow.

Affected products

  • GitLab GitLab: from 13.3.0, before 13.3.4 (fixed in 13.3.4)

Published 2020-09-14. Last modified 2026-06-17.