MEDIUM
CVE-2020-26408
CVSS
5.3
Description
A limited information disclosure vulnerability exists in Gitlab CE/EE from >= 12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2 that allows an attacker to view limited information in user's private profile
Summary dbcve.org
A broken access control vulnerability in GitLab CE/EE allows authenticated attackers to view limited information from user private profiles that should be restricted. The issue stems from insufficient permission checks on profile data access.
Mitigation
Upgrade GitLab to version 13.4.7, 13.5.5, 13.6.2 or later to resolve the broken access control in profile visibility.
Weakness (CWE)
CWE-862
Missing Authorization
EPSS Score
1.03%
Probability of exploitation in next 30 days
62.2th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.