CVE Published: 17/11/2020 |
CVE Updated: 04/08/2024 |
CVE Year: 2020 Source: GitLab |
Vendor: GitLab |
Product: GitLab EE Status : PUBLISHED
CVE-2020-26406 Description
Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This information was exposed through GraphQL to non-members of public projects with repository visibility restricted as well as guest members on private projects. Affected versions are: >=13.3, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.
Metrics
CVSS Version: 3.1 |
Base Score: 5.3 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N