GitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorization flow.
{ "binaries": [ { "binary_version": "8.5.8+dfsg-5", "binary_name": "gitlab" } ] }