VulnerabilityModified
CVE-2020-26406
Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3.
MEDIUM 5.3EPSS 1.44%
Does this matter?
Lower severity and a low EPSS score (1.44%). Track it; it rarely justifies an emergency change on its own.
Description
Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This information was exposed through GraphQL to non-members of public projects with repository visibility restricted as well as guest members on private projects. Affected versions are: >=13.3, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.44% probability · 72th percentile
- CISA KEV
- Not listed
- Affected
- gitlab/gitlab
- Source
- cve@gitlab.com
References
- https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26406.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/244921Broken Link
- https://hackerone.com/reports/965602Permissions Required, Third Party Advisory
- https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26406.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/244921Broken Link
- https://hackerone.com/reports/965602Permissions Required, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.