An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclosure via GraphQL results in user email being unexpectedly visible.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/244275 | broken link |
https://hackerone.com/reports/972355 | permissions required |
https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26413.json | vendor advisory |