CVE-2020-26406 Information
Jun 07, 2022
cve
Description
Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This information was exposed through GraphQL to non-members of public projects with repository visibility restricted as well as guest members on private projects. Affected versions are: >=13.3 <13.3.9>=13.4 <13.4.5>=13.5 <13.5.2.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Reference
https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26406.json https://hackerone.com/reports/965602 https://gitlab.com/gitlab-org/gitlab/-/issues/244921
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
5.3
Share on: