First published: Fri Dec 11 2020(Updated: )
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclosure via GraphQL results in user email being unexpectedly visible.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=13.4.0<13.6.2 | |
GitLab | >=13.4.0<13.6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-26413 is classified as a medium severity vulnerability due to information disclosure risks.
To fix CVE-2020-26413, upgrade your GitLab installation to version 13.6.2 or later.
CVE-2020-26413 may lead to unauthorized visibility of user email addresses through GraphQL queries.
CVE-2020-26413 affects all GitLab CE/EE versions from 13.4.0 up to, but not including, 13.6.2.
There is no official workaround for CVE-2020-26413, so upgrading is the recommended approach.