CVE-2020-26415 — Sensitive Information Exposure in Gitlab
Severity
4.3MEDIUMNVD
EPSS
0.2%
top 63.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 11
Latest updateMay 24
Description
Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 12.2 via the REST API. This affects GitLab >=12.2 to =13.5 to =13.6 to <13.6.2.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4
Affected Packages4 packages
🔴Vulnerability Details
2📋Vendor Advisories
2GitLab▶
CVE-2020-26415: Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 12.2 via the REST API. This affects Git↗2020-12-11
Debian▶
CVE-2020-26415: gitlab - Information about the starred projects for private user profiles was exposed via...↗2020