CVE-2020-26406
published 2020-11-17CVE-2020-26406: Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This information was exposed through GraphQL to…
PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
1.42%
69.8th percentile
Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This information was exposed through GraphQL to non-members of public projects with repository visibility restricted as well as guest members on private projects. Affected versions are: >=13.3, =13.4, =13.5, <13.5.2.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gitlab | — | — |
| gitlab | gitlab | — | — |
| gitlab | gitlab | >= 13.3.0 < 13.3.9 | 13.3.9 |
| gitlab | gitlab | >= 13.4.0 < 13.4.5 | 13.4.5 |
| gitlab | gitlab | >= 13.5.0 < 13.5.2 | 13.5.2 |
| gitlab | gitlab_ee | — | — |
| gitlab | gitlab_ee | — | — |
| gitlab | gitlab_ee | — | — |
| gitlab | gitlab_ee | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_debian5.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wx3j-3x93-528x: Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13
ghsa_unreviewed·2022-05-24
CVE-2020-26406 [MEDIUM] GHSA-wx3j-3x93-528x: Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13
Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This information was exposed through GraphQL to non-members of public projects with repository visibility restricted as well as guest members on private projects. Affected versions are: >=13.3, =13.4, =13.5, <13.5.2.
GitLab
CVE-2020-26406: Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This information was exposed through G
vendor_gitlab·2020-11-17·CVSS 5.3
CVE-2020-26406 [MEDIUM] CVE-2020-26406: Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This information was exposed through G
CVE-2020-26406: Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This information was exposed through GraphQL to non-members of public projects with repository visibility restricted as well as guest members on private projects. Affected versions are: >=13.3, =13.4, =13.5, <13.5.2.
Debian
CVE-2020-26406: gitlab - Certain SAST CiConfiguration information could be viewed by unauthorized users i...
vendor_debian·2020·CVSS 5.3
CVE-2020-26406 [MEDIUM] CVE-2020-26406: gitlab - Certain SAST CiConfiguration information could be viewed by unauthorized users i...
Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This information was exposed through GraphQL to non-members of public projects with repository visibility restricted as well as guest members on private projects. Affected versions are: >=13.3, =13.4, =13.5, <13.5.2.
Scope: local
sid: resolved
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26406.jsonhttps://gitlab.com/gitlab-org/gitlab/-/issues/244921https://hackerone.com/reports/965602https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26406.jsonhttps://gitlab.com/gitlab-org/gitlab/-/issues/244921https://hackerone.com/reports/965602
2020-11-17
Published