Vulnerability Details CVE-2020-26413
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclosure via GraphQL results in user email being unexpectedly visible.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.893
EPSS Ranking 99.5%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 5.0
Products affected by CVE-2020-26413
-
cpe:2.3:a:gitlab:gitlab:13.4.0
-
cpe:2.3:a:gitlab:gitlab:13.4.1
-
cpe:2.3:a:gitlab:gitlab:13.4.2
-
cpe:2.3:a:gitlab:gitlab:13.4.3
-
cpe:2.3:a:gitlab:gitlab:13.4.4
-
cpe:2.3:a:gitlab:gitlab:13.4.5
-
cpe:2.3:a:gitlab:gitlab:13.4.6
-
cpe:2.3:a:gitlab:gitlab:13.4.7
-
cpe:2.3:a:gitlab:gitlab:13.5.0
-
cpe:2.3:a:gitlab:gitlab:13.5.1
-
cpe:2.3:a:gitlab:gitlab:13.5.2
-
cpe:2.3:a:gitlab:gitlab:13.5.3
-
cpe:2.3:a:gitlab:gitlab:13.5.4
-
cpe:2.3:a:gitlab:gitlab:13.5.5
-
cpe:2.3:a:gitlab:gitlab:13.5.6
-
cpe:2.3:a:gitlab:gitlab:13.6.0
-
cpe:2.3:a:gitlab:gitlab:13.6.1