CVE-2020-26413
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclosure via GraphQL results in user email being unexpectedly visible.
Summary dbcve.org
GitLab CE/EE versions 13.4 through 13.6.1 contain an information disclosure vulnerability in the GraphQL API that unexpectedly exposes user email addresses to unauthorized parties. This flaw stems from insufficient access control checks in the GraphQL query handling, allowing authenticated or potentially unauthenticated users to query for email addresses they should not have access to.
Mitigation
Upgrade GitLab to version 13.6.2 or later to receive the vendor patch. Alternatively, restrict GraphQL API access or monitor for unauthorized email enumeration attempts until the upgrade can be performed.