Site icon API Security Blog

GitLab 13.4 < 13.4.7 / 13.5 < 13.5.5 / 13.6 < 13.6.2 (CVE-2020-26413)

The version of GitLab installed on the remote host is affected by a vulnerability, as follows: An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclosure via GraphQL results in user email being unexpectedly visible. (CVE-2020-26413) Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version…Read More

Exit mobile version