VulnerabilityModified
CVE-2020-26415
Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 12.2 via the REST API.
MEDIUM 4.3EPSS 0.83%
Does this matter?
Lower severity and a low EPSS score (0.83%). Track it; it rarely justifies an emergency change on its own.
Description
Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 12.2 via the REST API. This affects GitLab >=12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.83% probability · 55th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200, CWE-862
- Affected
- gitlab/gitlab
- Source
- cve@gitlab.com
References
- https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26415.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/277337Broken Link
- https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26415.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/277337Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.