CVE-2020-26413: Infoleak
Published Dec 11, 2020
·Updated
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclosure via GraphQL results in user email being unexpectedly visible.
Affected Software
2 affected components
GitLab GitLab>=13.4.0<13.6.2
GitLab GitLab>=13.4.0<13.6.2
Event History
Dec 11, 2020
CVE Published
via MITRE·03:47 AM
Data Sourced
via MITRE·03:47 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-26413?
CVE-2020-26413 is classified as a medium severity vulnerability due to information disclosure risks.
2
How do I fix CVE-2020-26413?
To fix CVE-2020-26413, upgrade your GitLab installation to version 13.6.2 or later.
3
What kind of information is exposed by CVE-2020-26413?
CVE-2020-26413 may lead to unauthorized visibility of user email addresses through GraphQL queries.
4
Which versions of GitLab are affected by CVE-2020-26413?
CVE-2020-26413 affects all GitLab CE/EE versions from 13.4.0 up to, but not including, 13.6.2.
5
Is there a workaround for CVE-2020-26413 before applying the fix?
There is no official workaround for CVE-2020-26413, so upgrading is the recommended approach.