VulnerabilityModified
CVE-2020-26416
Information disclosure in Advanced Search component of GitLab EE starting from 8.4 results in exposure of search terms via Rails logs.
MEDIUM 4.4EPSS 0.33%
Does this matter?
Lower severity and a low EPSS score (0.33%). Track it; it rarely justifies an emergency change on its own.
Description
Information disclosure in Advanced Search component of GitLab EE starting from 8.4 results in exposure of search terms via Rails logs. This affects versions >=8.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.
- CVSS 3.1
- 4.4 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.33% probability · 26th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-532
- Affected
- gitlab/gitlab
- Source
- cve@gitlab.com
References
- https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26416.jsonThird Party Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/244495Broken Link
- https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26416.jsonThird Party Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/244495Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.