In GitLab before 13.0.12, 13.1.6 and 13.2.3, it is possible to bypass E-mail verification which is required for OAuth Flow.
2020-08-10T14:15:12.813
2024-11-21T05:00:57.993
Modified
CVSSv3.1: 9.6 (CRITICAL)
AV:N/AC:L/Au:S/C:P/I:P/A:N
8.0
4.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | gitlab | gitlab | < 13.0.12 | Yes |
| Application | gitlab | gitlab | < 13.1.6 | Yes |
| Application | gitlab | gitlab | < 13.2.3 | Yes |