MEDIUM

CVE-2020-26413

Gitlab GitLab 2020-12-11 CVSS v3.1
CVSS
5.3

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclosure via GraphQL results in user email being unexpectedly visible.

Summary dbcve.org

GitLab CE/EE versions 13.4 through 13.6.1 contain an information disclosure vulnerability in the GraphQL API that unexpectedly exposes user email addresses to unauthorized parties. This flaw stems from insufficient access control checks in the GraphQL query handling, allowing authenticated or potentially unauthenticated users to query for email addresses they should not have access to.

Mitigation

Upgrade GitLab to version 13.6.2 or later to receive the vendor patch. Alternatively, restrict GraphQL API access or monitor for unauthorized email enumeration attempts until the upgrade can be performed.

Weakness (CWE)

CWE-200 Information Exposure

EPSS Score

34.93%
Probability of exploitation in next 30 days
98.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE