Risk Scores
CVSS v3.1
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | gitlab | 13.3.0, 13.3.0, 13.3.0 |
Timeline
- Mar 6, 2024 CVE Published
- Apr 3, 2025 CVE Updated
GitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorization flow.
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | gitlab | 13.3.0, 13.3.0, 13.3.0 |