CVE-2020-13292 - CERT CVE
ID CVE-2020-13292
Sažetak In GitLab before 13.0.12, 13.1.6 and 13.2.3, it is possible to bypass E-mail verification which is required for OAuth Flow.
Reference
CVSS
Base: 5.5
Impact: 4.9
Exploitability:8.0
Pristup
VektorSloženostAutentikacija
NETWORK LOW SINGLE
Impact
PovjerljivostCjelovitostDostupnost
PARTIAL PARTIAL NONE
CVSS vektor AV:N/AC:L/Au:S/C:P/I:P/A:N
Zadnje važnije ažuriranje 11-08-2020 - 18:13
Objavljeno 10-08-2020 - 14:15