MEDIUM

CVE-2020-26408

Gitlab GitLab 2020-12-11 CVSS v3.1
CVSS
5.3

Description

A limited information disclosure vulnerability exists in Gitlab CE/EE from >= 12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2 that allows an attacker to view limited information in user's private profile

Summary dbcve.org

A broken access control vulnerability in GitLab CE/EE allows authenticated attackers to view limited information from user private profiles that should be restricted. The issue stems from insufficient permission checks on profile data access.

Mitigation

Upgrade GitLab to version 13.4.7, 13.5.5, 13.6.2 or later to resolve the broken access control in profile visibility.

Weakness (CWE)

CWE-862 Missing Authorization

EPSS Score

1.03%
Probability of exploitation in next 30 days
62.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE