CVE-2020-26415Sensitive Information Exposure in Gitlab

Severity
4.3MEDIUMNVD
EPSS
0.2%
top 63.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 11
Latest updateMay 24

Description

Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 12.2 via the REST API. This affects GitLab >=12.2 to =13.5 to =13.6 to <13.6.2.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages4 packages

NVDgitlab/gitlab12.2.013.4.7+2
debiandebian/gitlab< gitlab 13.4.7-1 (sid)
CVEListV5gitlab/gitlab>=12.2 to <13.4.7, >=13.5 to <13.5.5, >=13.6 to <13.6.2+2
gitlabgitlab/gitlab

🔴Vulnerability Details

2
GHSA
GHSA-48fw-3qmc-rmp7: Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 122022-05-24
OSV
CVE-2020-26415: Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 122020-12-11

📋Vendor Advisories

2
GitLab
CVE-2020-26415: Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 12.2 via the REST API. This affects Git2020-12-11
Debian
CVE-2020-26415: gitlab - Information about the starred projects for private user profiles was exposed via...2020